{"api_version":"1","generated_at":"2026-07-23T07:17:41+00:00","cve":"CVE-2005-3959","urls":{"html":"https://cve.report/CVE-2005-3959","api":"https://cve.report/api/cve/CVE-2005-3959.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3959","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3959"},"summary":{"title":"CVE-2005-3959","description":"Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-01 06:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/17783","name":"http://secunia.com/advisories/17783","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - FreeWebStat Script Insertion Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.freewebstat.com/changelog-english.html","name":"http://www.freewebstat.com/changelog-english.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"free web stat,web statistic,web tracker,logfile analyzer,website tracking","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21207","name":"http://www.osvdb.org/21207","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.ush.it/2005/11/25/free-web-stat/","name":"http://www.ush.it/2005/11/25/free-web-stat/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"ush.it - a beautiful place » Free Web Stat Multiple XSS Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23391","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23391","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/417902/100/0/threaded","name":"http://www.securityfocus.com/archive/1/417902/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23387","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015301","name":"http://securitytracker.com/id?1015301","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - FreeWebStat Input Validation Holes Permit Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15601","name":"http://www.securityfocus.com/bid/15601","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"FreeWebStat Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2646","name":"http://www.vupen.com/english/advisories/2005/2646","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3959","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3959","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"freewebstat","cpe5":"freewebstat","cpe6":"1.0_rev37","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:31:49.084Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"freewebstat-stat-search-xss(23391)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23391"},{"name":"17783","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17783"},{"name":"20051128 Free Web Stat Multiple XSS Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/417902/100/0/threaded"},{"name":"1015301","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015301"},{"name":"ADV-2005-2646","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2646"},{"name":"15601","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15601"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.freewebstat.com/changelog-english.html"},{"name":"21207","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21207"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ush.it/2005/11/25/free-web-stat/"},{"name":"freewebstat-logdb-xss(23387)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23387"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"freewebstat-stat-search-xss(23391)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23391"},{"name":"17783","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17783"},{"name":"20051128 Free Web Stat Multiple XSS Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/417902/100/0/threaded"},{"name":"1015301","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015301"},{"name":"ADV-2005-2646","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2646"},{"name":"15601","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15601"},{"tags":["x_refsource_MISC"],"url":"http://www.freewebstat.com/changelog-english.html"},{"name":"21207","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21207"},{"tags":["x_refsource_MISC"],"url":"http://www.ush.it/2005/11/25/free-web-stat/"},{"name":"freewebstat-logdb-xss(23387)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23387"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3959","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"freewebstat-stat-search-xss(23391)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23391"},{"name":"17783","refsource":"SECUNIA","url":"http://secunia.com/advisories/17783"},{"name":"20051128 Free Web Stat Multiple XSS Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/417902/100/0/threaded"},{"name":"1015301","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015301"},{"name":"ADV-2005-2646","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2646"},{"name":"15601","refsource":"BID","url":"http://www.securityfocus.com/bid/15601"},{"name":"http://www.freewebstat.com/changelog-english.html","refsource":"MISC","url":"http://www.freewebstat.com/changelog-english.html"},{"name":"21207","refsource":"OSVDB","url":"http://www.osvdb.org/21207"},{"name":"http://www.ush.it/2005/11/25/free-web-stat/","refsource":"MISC","url":"http://www.ush.it/2005/11/25/free-web-stat/"},{"name":"freewebstat-logdb-xss(23387)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23387"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3959","datePublished":"2005-12-01T11:00:00.000Z","dateReserved":"2005-12-01T00:00:00.000Z","dateUpdated":"2024-08-07T23:31:49.084Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-01 06:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:freewebstat:freewebstat:1.0_rev37:*:*:*:*:*:*:*","matchCriteriaId":"33E66E98-6A87-481E-ACEA-917AEEA2D26E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3959","Ordinal":"1","Title":"CVE-2005-3959","CVE":"CVE-2005-3959","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3959","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.","Type":"Description","Title":"CVE-2005-3959"},{"CveYear":"2005","CveId":"3959","Ordinal":"2","NoteData":"2005-12-01","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3959","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}