{"api_version":"1","generated_at":"2026-07-23T09:58:53+00:00","cve":"CVE-2005-3866","urls":{"html":"https://cve.report/CVE-2005-3866","api":"https://cve.report/api/cve/CVE-2005-3866.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3866","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3866"},"summary":{"title":"CVE-2005-3866","description":"Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-29 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/15612","name":"http://www.securityfocus.com/bid/15612","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SearchSolutions Multiple Products Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: SearchFeed Search Engine XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21144","name":"http://www.osvdb.org/21144","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/17715","name":"http://secunia.com/advisories/17715","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - SearchFeed Search Engine Script \"REQ\" Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23348","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2609","name":"http://www.vupen.com/english/advisories/2005/2609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3866","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3866","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3866","vulnerable":"1","versionEndIncluding":"1.3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wwwsearchsolutions","cpe5":"searchfeed_search_engine","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.512Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17715","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17715"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html"},{"name":"searchfeed-search-xss(23348)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23348"},{"name":"15612","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15612"},{"name":"ADV-2005-2609","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2609"},{"name":"21144","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21144"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17715","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17715"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html"},{"name":"searchfeed-search-xss(23348)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23348"},{"name":"15612","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15612"},{"name":"ADV-2005-2609","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2609"},{"name":"21144","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21144"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3866","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17715","refsource":"SECUNIA","url":"http://secunia.com/advisories/17715"},{"name":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html"},{"name":"searchfeed-search-xss(23348)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23348"},{"name":"15612","refsource":"BID","url":"http://www.securityfocus.com/bid/15612"},{"name":"ADV-2005-2609","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2609"},{"name":"21144","refsource":"OSVDB","url":"http://www.osvdb.org/21144"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3866","datePublished":"2005-11-29T11:00:00.000Z","dateReserved":"2005-11-29T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.512Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-29 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wwwsearchsolutions:searchfeed_search_engine:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.2","matchCriteriaId":"39F1BB3D-E4E7-4DD4-9C4E-F44EF49CCE5A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3866","Ordinal":"1","Title":"CVE-2005-3866","CVE":"CVE-2005-3866","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3866","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.","Type":"Description","Title":"CVE-2005-3866"},{"CveYear":"2005","CveId":"3866","Ordinal":"2","NoteData":"2005-11-29","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3866","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}