{"api_version":"1","generated_at":"2026-07-23T08:52:50+00:00","cve":"CVE-2005-2416","urls":{"html":"https://cve.report/CVE-2005-2416","api":"https://cve.report/api/cve/CVE-2005-2416.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2416","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2416"},"summary":{"title":"CVE-2005-2416","description":"Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21487","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21487","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21484","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21484","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16169","name":"http://secunia.com/advisories/16169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contrexx CMS Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14352","name":"http://www.securityfocus.com/bid/14352","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contrexx Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/18168","name":"http://www.osvdb.org/18168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2","name":"http://marc.info/?l=bugtraq&m=112206702015439&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Advisory 11/2005: Multiple vulnerabilities in Contrexx' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hardened-php.net/advisory_112005.59.html","name":"http://www.hardened-php.net/advisory_112005.59.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Hardened-PHP Project - PHP Security\n\n      - Advisory 11/2005","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014554","name":"http://securitytracker.com/id?1014554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Contrexx Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/18169","name":"http://www.osvdb.org/18169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2416","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2416","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2416","vulnerable":"1","versionEndIncluding":"1.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"astalavista_it_engineering","cpe5":"contrexx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:22:49.162Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014554","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014554"},{"name":"18168","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18168"},{"name":"contrexx-search-xss(21484)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21484"},{"name":"16169","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16169"},{"name":"contrexx-blog-xss(21487)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21487"},{"name":"18169","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14352"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hardened-php.net/advisory_112005.59.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014554","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014554"},{"name":"18168","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18168"},{"name":"contrexx-search-xss(21484)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21484"},{"name":"16169","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16169"},{"name":"contrexx-blog-xss(21487)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21487"},{"name":"18169","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14352"},{"tags":["x_refsource_MISC"],"url":"http://www.hardened-php.net/advisory_112005.59.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2416","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014554","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014554"},{"name":"18168","refsource":"OSVDB","url":"http://www.osvdb.org/18168"},{"name":"contrexx-search-xss(21484)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21484"},{"name":"16169","refsource":"SECUNIA","url":"http://secunia.com/advisories/16169"},{"name":"contrexx-blog-xss(21487)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21487"},{"name":"18169","refsource":"OSVDB","url":"http://www.osvdb.org/18169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","refsource":"BID","url":"http://www.securityfocus.com/bid/14352"},{"name":"http://www.hardened-php.net/advisory_112005.59.html","refsource":"MISC","url":"http://www.hardened-php.net/advisory_112005.59.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2416","datePublished":"2005-08-03T04:00:00.000Z","dateReserved":"2005-08-03T00:00:00.000Z","dateUpdated":"2024-08-07T22:22:49.162Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:astalavista_it_engineering:contrexx:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.4","matchCriteriaId":"3B18553E-DB63-4EB4-96AC-FA93E9F11B7A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2416","Ordinal":"1","Title":"CVE-2005-2416","CVE":"CVE-2005-2416","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2416","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.","Type":"Description","Title":"CVE-2005-2416"},{"CveYear":"2005","CveId":"2416","Ordinal":"2","NoteData":"2005-08-03","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2416","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}