{"api_version":"1","generated_at":"2026-07-23T08:49:11+00:00","cve":"CVE-2005-1186","urls":{"html":"https://cve.report/CVE-2005-1186","api":"https://cve.report/api/cve/CVE-2005-1186.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1186","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1186"},"summary":{"title":"CVE-2005-1186","description":"Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1013718","name":"http://securitytracker.com/id?1013718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - Musicmatch Jukebox Lets Local Users Gain Elevated Privileges and Remote Users Conduct Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20129","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20129","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/lists/bugtraq/2005/Apr/0212.html","name":"http://seclists.org/lists/bugtraq/2005/Apr/0212.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Bugtraq: Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hyperdose.com/advisories/H2005-04.txt","name":"http://www.hyperdose.com/advisories/H2005-04.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"WebHost4Life","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1186","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1186","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1186","vulnerable":"1","versionEndIncluding":"10.00.2047","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"musicmatch","cpe5":"jukebox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:44:05.269Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hyperdose.com/advisories/H2005-04.txt"},{"name":"20050414 Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://seclists.org/lists/bugtraq/2005/Apr/0212.html"},{"name":"jukebox-mmfwlaunch-gain-privileges(20129)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20129"},{"name":"1013718","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1013718"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-04-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.hyperdose.com/advisories/H2005-04.txt"},{"name":"20050414 Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://seclists.org/lists/bugtraq/2005/Apr/0212.html"},{"name":"jukebox-mmfwlaunch-gain-privileges(20129)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20129"},{"name":"1013718","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1013718"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1186","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.hyperdose.com/advisories/H2005-04.txt","refsource":"MISC","url":"http://www.hyperdose.com/advisories/H2005-04.txt"},{"name":"20050414 Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch","refsource":"BUGTRAQ","url":"http://seclists.org/lists/bugtraq/2005/Apr/0212.html"},{"name":"jukebox-mmfwlaunch-gain-privileges(20129)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20129"},{"name":"1013718","refsource":"SECTRACK","url":"http://securitytracker.com/id?1013718"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1186","datePublished":"2005-04-19T04:00:00.000Z","dateReserved":"2005-04-19T00:00:00.000Z","dateUpdated":"2024-08-07T21:44:05.269Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:musicmatch:jukebox:*:*:*:*:*:*:*:*","versionEndIncluding":"10.00.2047","matchCriteriaId":"3A1ABCF7-6FBF-44D3-8AC9-1F16A8924E5F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1186","Ordinal":"1","Title":"CVE-2005-1186","CVE":"CVE-2005-1186","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1186","Ordinal":"1","NoteData":"Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.","Type":"Description","Title":"CVE-2005-1186"},{"CveYear":"2005","CveId":"1186","Ordinal":"2","NoteData":"2005-04-19","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1186","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}