{"api_version":"1","generated_at":"2026-07-24T22:37:36+00:00","cve":"CVE-2005-2202","urls":{"html":"https://cve.report/CVE-2005-2202","api":"https://cve.report/api/cve/CVE-2005-2202.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2202","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2202"},"summary":{"title":"CVE-2005-2202","description":"Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-07-11 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/15970","name":"http://secunia.com/advisories/15970","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Xerox WorkCentre Pro Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014429","name":"http://securitytracker.com/id?1014429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Xerox WorkCentre Pro Web Service Lets Remote Users Bypass Authentication, Obtain Files, Modify Web Pages, or Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf","name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2202","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2202","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_2128","cpe6":"0.001.04.044","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_2128","cpe6":"0.001.04.504","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_2636","cpe6":"0.001.04.044","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_2636","cpe6":"0.001.04.504","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_3545","cpe6":"0.001.04.044","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_3545","cpe6":"0.001.04.504","cpe7":"*","cpe8":"pro_color","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:15:37.776Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf"},{"name":"15970","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15970"},{"name":"1014429","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014429"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-07-11T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf"},{"name":"15970","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15970"},{"name":"1014429","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014429"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2202","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf","refsource":"CONFIRM","url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf"},{"name":"15970","refsource":"SECUNIA","url":"http://secunia.com/advisories/15970"},{"name":"1014429","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014429"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2202","datePublished":"2005-07-11T04:00:00.000Z","dateReserved":"2005-07-11T00:00:00.000Z","dateUpdated":"2024-09-17T00:16:35.520Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-07-11 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_2128:0.001.04.044:*:pro_color:*:*:*:*:*","matchCriteriaId":"EA305D4F-4307-4043-A749-B6BA0B8A8492"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_2128:0.001.04.504:*:pro_color:*:*:*:*:*","matchCriteriaId":"83C173B0-F30E-4AE6-9B1F-2D7C146EC620"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_2636:0.001.04.044:*:pro_color:*:*:*:*:*","matchCriteriaId":"89D31C14-FC15-456F-A5A3-3DD081C87CBC"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_2636:0.001.04.504:*:pro_color:*:*:*:*:*","matchCriteriaId":"CD92B28A-F518-4056-90C8-6FEDE91E75F5"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_3545:0.001.04.044:*:pro_color:*:*:*:*:*","matchCriteriaId":"4FE28C1C-E8D2-4161-B441-26A70E6C9A78"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_3545:0.001.04.504:*:pro_color:*:*:*:*:*","matchCriteriaId":"FA63412F-EB3C-4D33-AFA2-01FCED65EF9C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2202","Ordinal":"1","Title":"CVE-2005-2202","CVE":"CVE-2005-2202","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2202","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.","Type":"Description","Title":"CVE-2005-2202"},{"CveYear":"2005","CveId":"2202","Ordinal":"2","NoteData":"2005-07-11","Type":"Other","Title":"Published"}]}}}