{"api_version":"1","generated_at":"2026-07-23T08:17:38+00:00","cve":"CVE-2005-2488","urls":{"html":"https://cve.report/CVE-2005-2488","api":"https://cve.report/api/cve/CVE-2005-2488.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2488","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2488"},"summary":{"title":"CVE-2005-2488","description":"Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-07 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21689","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21689","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16317","name":"http://secunia.com/advisories/16317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - web content management Cross-Site Scripting and Authentication Bypass","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.rgod.altervista.org/webc.html","name":"http://www.rgod.altervista.org/webc.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014616","name":"http://securitytracker.com/id?1014616","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - 'web content management' Lets Remote Users Add Administrative Accounts or Conduct Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14464","name":"http://www.securityfocus.com/bid/14464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Web Content Management Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2488","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2488","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2488","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"web_content_management","cpe5":"web_content_management_news_system","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:30:01.067Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rgod.altervista.org/webc.html"},{"name":"16317","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16317"},{"name":"14464","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14464"},{"name":"webcms-multiple-script-xss(21689)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21689"},{"name":"1014616","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014616"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-08-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.rgod.altervista.org/webc.html"},{"name":"16317","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16317"},{"name":"14464","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14464"},{"name":"webcms-multiple-script-xss(21689)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21689"},{"name":"1014616","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014616"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2488","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.rgod.altervista.org/webc.html","refsource":"MISC","url":"http://www.rgod.altervista.org/webc.html"},{"name":"16317","refsource":"SECUNIA","url":"http://secunia.com/advisories/16317"},{"name":"14464","refsource":"BID","url":"http://www.securityfocus.com/bid/14464"},{"name":"webcms-multiple-script-xss(21689)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21689"},{"name":"1014616","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014616"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2488","datePublished":"2005-08-07T04:00:00.000Z","dateReserved":"2005-08-07T00:00:00.000Z","dateUpdated":"2024-08-07T22:30:01.067Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-07 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:web_content_management:web_content_management_news_system:*:*:*:*:*:*:*:*","matchCriteriaId":"97C33549-F03B-4F35-A520-6EE57133F8C1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2488","Ordinal":"1","Title":"CVE-2005-2488","CVE":"CVE-2005-2488","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2488","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.","Type":"Description","Title":"CVE-2005-2488"},{"CveYear":"2005","CveId":"2488","Ordinal":"2","NoteData":"2005-08-07","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2488","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}