{"api_version":"1","generated_at":"2026-07-24T18:45:45+00:00","cve":"CVE-2005-2721","urls":{"html":"https://cve.report/CVE-2005-2721","api":"https://cve.report/api/cve/CVE-2005-2721.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2721","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2721"},"summary":{"title":"CVE-2005-2721","description":"Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-30 11:45:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/16565/","name":"http://secunia.com/advisories/16565/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Foojan WMS \"Referer\" HTTP Header Script Insertion","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112491140712884&w=2","name":"http://marc.info/?l=bugtraq&m=112491140712884&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Foojan PHP Weblog Information Disclosure - Refferer Html Injection' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14658","name":"http://www.securityfocus.com/bid/14658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Foojan PHPWeblog Html Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22004","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2721","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2721","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2721","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"foojan","cpe5":"php_weblog","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:45:02.157Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16565","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16565/"},{"name":"foojan-referer-code-execution(22004)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22004"},{"name":"14658","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14658"},{"name":"20050824 Foojan PHP Weblog Information Disclosure - Refferer Html Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112491140712884&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-08-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16565","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16565/"},{"name":"foojan-referer-code-execution(22004)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22004"},{"name":"14658","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14658"},{"name":"20050824 Foojan PHP Weblog Information Disclosure - Refferer Html Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112491140712884&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2721","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16565","refsource":"SECUNIA","url":"http://secunia.com/advisories/16565/"},{"name":"foojan-referer-code-execution(22004)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22004"},{"name":"14658","refsource":"BID","url":"http://www.securityfocus.com/bid/14658"},{"name":"20050824 Foojan PHP Weblog Information Disclosure - Refferer Html Injection","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112491140712884&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2721","datePublished":"2005-08-29T04:00:00.000Z","dateReserved":"2005-08-29T00:00:00.000Z","dateUpdated":"2024-08-07T22:45:02.157Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-30 11:45:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:foojan:php_weblog:*:*:*:*:*:*:*:*","matchCriteriaId":"4B4D6F5C-5D59-49FB-ABA6-1F30E6D22B3E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2721","Ordinal":"1","Title":"CVE-2005-2721","CVE":"CVE-2005-2721","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2721","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.","Type":"Description","Title":"CVE-2005-2721"},{"CveYear":"2005","CveId":"2721","Ordinal":"2","NoteData":"2005-08-29","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2721","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}