{"api_version":"1","generated_at":"2026-07-23T11:31:24+00:00","cve":"CVE-2005-1282","urls":{"html":"https://cve.report/CVE-2005-1282","api":"https://cve.report/api/cve/CVE-2005-1282.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1282","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1282"},"summary":{"title":"CVE-2005-1282","description":"Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=111419001527077&w=2","name":"http://marc.info/?l=bugtraq&m=111419001527077&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/15100","name":"http://secunia.com/advisories/15100","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Argosoft Mail Server Cross-Site Scripting and Script Insertion","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20225","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20225","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13326","name":"http://www.securityfocus.com/bid/13326","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ArGoSoft Mail Server Email Message HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1282","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1282","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"argosoft","cpe5":"argosoft_mail_server","cpe6":"1.8.7.6","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:44:06.286Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111419001527077&w=2"},{"name":"argosoft-mail-server-html-tag-filter-xss(20225)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20225"},{"name":"15100","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15100"},{"name":"13326","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13326"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-04-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111419001527077&w=2"},{"name":"argosoft-mail-server-html-tag-filter-xss(20225)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20225"},{"name":"15100","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15100"},{"name":"13326","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13326"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1282","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111419001527077&w=2"},{"name":"argosoft-mail-server-html-tag-filter-xss(20225)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20225"},{"name":"15100","refsource":"SECUNIA","url":"http://secunia.com/advisories/15100"},{"name":"13326","refsource":"BID","url":"http://www.securityfocus.com/bid/13326"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1282","datePublished":"2005-04-26T04:00:00.000Z","dateReserved":"2005-04-26T00:00:00.000Z","dateUpdated":"2024-08-07T21:44:06.286Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:argosoft:argosoft_mail_server:1.8.7.6:*:pro:*:*:*:*:*","matchCriteriaId":"07FA7F76-B59E-4E14-88C6-B9BAD88E90C0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1282","Ordinal":"1","Title":"CVE-2005-1282","CVE":"CVE-2005-1282","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1282","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.","Type":"Description","Title":"CVE-2005-1282"},{"CveYear":"2005","CveId":"1282","Ordinal":"2","NoteData":"2005-04-26","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1282","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}