{"api_version":"1","generated_at":"2026-07-23T08:13:42+00:00","cve":"CVE-2005-1561","urls":{"html":"https://cve.report/CVE-2005-1561","api":"https://cve.report/api/cve/CVE-2005-1561.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1561","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1561"},"summary":{"title":"CVE-2005-1561","description":"Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-11 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=111584883727605&w=2","name":"http://marc.info/?l=bugtraq&m=111584883727605&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15329","name":"http://secunia.com/advisories/15329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Secunia - Advisories - MaxWebPortal Cross-Site Scripting and SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/16501","name":"http://www.osvdb.org/16501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/13601","name":"http://www.securityfocus.com/bid/13601","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MaxWebPortal Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20560","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20560","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hackerscenter.com/archive/view.asp?id=2542","name":"http://www.hackerscenter.com/archive/view.asp?id=2542","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"[HSC] MaxWebPortal Multiple SQL injection and XSS : Hackers Center : Internet Security Archive: Exploits, Patch, Security Articles, Advisories","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1561","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1561","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxwebportal","cpe5":"maxwebportal","cpe6":"1.3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:51:50.306Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111584883727605&w=2"},{"name":"maxwebportal-postasp-xss(20560)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20560"},{"name":"16501","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/16501"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hackerscenter.com/archive/view.asp?id=2542"},{"name":"15329","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15329"},{"name":"13601","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13601"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-05-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111584883727605&w=2"},{"name":"maxwebportal-postasp-xss(20560)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20560"},{"name":"16501","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/16501"},{"tags":["x_refsource_MISC"],"url":"http://www.hackerscenter.com/archive/view.asp?id=2542"},{"name":"15329","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15329"},{"name":"13601","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13601"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1561","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111584883727605&w=2"},{"name":"maxwebportal-postasp-xss(20560)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20560"},{"name":"16501","refsource":"OSVDB","url":"http://www.osvdb.org/16501"},{"name":"http://www.hackerscenter.com/archive/view.asp?id=2542","refsource":"MISC","url":"http://www.hackerscenter.com/archive/view.asp?id=2542"},{"name":"15329","refsource":"SECUNIA","url":"http://secunia.com/advisories/15329"},{"name":"13601","refsource":"BID","url":"http://www.securityfocus.com/bid/13601"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1561","datePublished":"2005-05-14T04:00:00.000Z","dateReserved":"2005-05-14T00:00:00.000Z","dateUpdated":"2024-08-07T21:51:50.306Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-11 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"DD43E028-53FC-475E-8E62-5660E2E93265"},{"vulnerable":true,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.3.1:*:*:*:*:*:*:*","matchCriteriaId":"9DFAB9F0-D654-4ADE-A54A-C3FC7675CC1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.3.2:*:*:*:*:*:*:*","matchCriteriaId":"33D88D67-858C-4A64-9EAC-C9634183F696"},{"vulnerable":true,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.3.3:*:*:*:*:*:*:*","matchCriteriaId":"0B875DE4-9AEC-4172-9E2D-60651F846B9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:maxwebportal:maxwebportal:1.3.5:*:*:*:*:*:*:*","matchCriteriaId":"448A15D5-BB55-4B4D-8751-829A00E644B1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1561","Ordinal":"1","Title":"CVE-2005-1561","CVE":"CVE-2005-1561","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1561","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.","Type":"Description","Title":"CVE-2005-1561"},{"CveYear":"2005","CveId":"1561","Ordinal":"2","NoteData":"2005-05-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1561","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}