{"api_version":"1","generated_at":"2026-07-23T09:31:38+00:00","cve":"CVE-2005-3867","urls":{"html":"https://cve.report/CVE-2005-3867","api":"https://cve.report/api/cve/CVE-2005-3867.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3867","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3867"},"summary":{"title":"CVE-2005-3867","description":"Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-29 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/15612","name":"http://www.securityfocus.com/bid/15612","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SearchSolutions Multiple Products Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/16129","name":"http://www.securityfocus.com/bid/16129","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RevenuePilot Search Engine Search Parameters Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/17717","name":"http://secunia.com/advisories/17717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - RevenuePilot Search Engine Script \"REQ\" Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: RevenuePilot Search Engine XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23345","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2607","name":"http://www.vupen.com/english/advisories/2005/2607","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21143","name":"http://www.osvdb.org/21143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3867","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3867","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3867","vulnerable":"1","versionEndIncluding":"1.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wwwsearchsolutions","cpe5":"revenuepilot_search_engine_script","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.527Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html"},{"name":"21143","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21143"},{"name":"revenuepilot-search-xss(23345)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23345"},{"name":"15612","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15612"},{"name":"16129","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16129"},{"name":"17717","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17717"},{"name":"ADV-2005-2607","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2607"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html"},{"name":"21143","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21143"},{"name":"revenuepilot-search-xss(23345)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23345"},{"name":"15612","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15612"},{"name":"16129","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16129"},{"name":"17717","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17717"},{"name":"ADV-2005-2607","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2607"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3867","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html"},{"name":"21143","refsource":"OSVDB","url":"http://www.osvdb.org/21143"},{"name":"revenuepilot-search-xss(23345)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23345"},{"name":"15612","refsource":"BID","url":"http://www.securityfocus.com/bid/15612"},{"name":"16129","refsource":"BID","url":"http://www.securityfocus.com/bid/16129"},{"name":"17717","refsource":"SECUNIA","url":"http://secunia.com/advisories/17717"},{"name":"ADV-2005-2607","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2607"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3867","datePublished":"2005-11-29T11:00:00.000Z","dateReserved":"2005-11-29T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.527Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-29 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wwwsearchsolutions:revenuepilot_search_engine_script:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.0","matchCriteriaId":"719EA3AE-8C37-4227-84C6-150F568037AB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3867","Ordinal":"1","Title":"CVE-2005-3867","CVE":"CVE-2005-3867","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3867","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search.","Type":"Description","Title":"CVE-2005-3867"},{"CveYear":"2005","CveId":"3867","Ordinal":"2","NoteData":"2005-11-29","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3867","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}