{"api_version":"1","generated_at":"2026-07-23T12:24:29+00:00","cve":"CVE-2005-3851","urls":{"html":"https://cve.report/CVE-2005-3851","api":"https://cve.report/api/cve/CVE-2005-3851.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3851","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3851"},"summary":{"title":"CVE-2005-3851","description":"Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-27 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/21095","name":"http://www.osvdb.org/21095","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/17712","name":"http://secunia.com/advisories/17712","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - OASYS Lite \"keyword\" Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15605","name":"http://www.securityfocus.com/bid/15605","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OASYS Lite Search.ASP Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2583","name":"http://www.vupen.com/english/advisories/2005/2583","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: OASYS Lite 1.0 \"search.asp\" XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3851","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3851","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3851","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"onlinetechtools.com","cpe5":"oasys_lite","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.578Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21095","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21095"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html"},{"name":"17712","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17712"},{"name":"ADV-2005-2583","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2583"},{"name":"15605","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15605"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-01T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21095","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21095"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html"},{"name":"17712","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17712"},{"name":"ADV-2005-2583","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2583"},{"name":"15605","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15605"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3851","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21095","refsource":"OSVDB","url":"http://www.osvdb.org/21095"},{"name":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/oasys-lite-10-searchasp-xss-vuln.html"},{"name":"17712","refsource":"SECUNIA","url":"http://secunia.com/advisories/17712"},{"name":"ADV-2005-2583","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2583"},{"name":"15605","refsource":"BID","url":"http://www.securityfocus.com/bid/15605"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3851","datePublished":"2005-11-27T11:00:00.000Z","dateReserved":"2005-11-27T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.578Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-27 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:onlinetechtools.com:oasys_lite:1.0:*:*:*:*:*:*:*","matchCriteriaId":"3CEEEFB7-ED99-4F5B-85B8-C0AF8A5613A3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3851","Ordinal":"1","Title":"CVE-2005-3851","CVE":"CVE-2005-3851","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3851","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.","Type":"Description","Title":"CVE-2005-3851"},{"CveYear":"2005","CveId":"3851","Ordinal":"2","NoteData":"2005-11-27","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3851","Ordinal":"3","NoteData":"2005-12-01","Type":"Other","Title":"Modified"}]}}}