{"api_version":"1","generated_at":"2026-07-23T10:42:11+00:00","cve":"CVE-2005-4057","urls":{"html":"https://cve.report/CVE-2005-4057","api":"https://cve.report/api/cve/CVE-2005-4057.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4057","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4057"},"summary":{"title":"CVE-2005-4057","description":"Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-07 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html","name":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: PluggedOut Nexus SQL&XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21479","name":"http://www.osvdb.org/21479","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2751","name":"http://www.vupen.com/english/advisories/2005/2751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15724","name":"http://www.securityfocus.com/bid/15724","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PluggedOut Nexus Search Script Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/17909","name":"http://secunia.com/advisories/17909","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - PluggedOut Nexus SQL Injection and Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4057","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4057","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jonathan_beckett","cpe5":"pluggedout_nexus","cpe6":"0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:31:48.990Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html"},{"name":"15724","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15724"},{"name":"ADV-2005-2751","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2751"},{"name":"21479","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21479"},{"name":"17909","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17909"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-12T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html"},{"name":"15724","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15724"},{"name":"ADV-2005-2751","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2751"},{"name":"21479","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21479"},{"name":"17909","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17909"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4057","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/pluggedout-nexus-sqlxss-vuln_06.html"},{"name":"15724","refsource":"BID","url":"http://www.securityfocus.com/bid/15724"},{"name":"ADV-2005-2751","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2751"},{"name":"21479","refsource":"OSVDB","url":"http://www.osvdb.org/21479"},{"name":"17909","refsource":"SECUNIA","url":"http://secunia.com/advisories/17909"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4057","datePublished":"2005-12-07T11:00:00.000Z","dateReserved":"2005-12-07T00:00:00.000Z","dateUpdated":"2024-08-07T23:31:48.990Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-07 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jonathan_beckett:pluggedout_nexus:0.1:*:*:*:*:*:*:*","matchCriteriaId":"8CEEBD65-DBDC-4A3E-8DF0-09605C3E38B7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4057","Ordinal":"1","Title":"CVE-2005-4057","CVE":"CVE-2005-4057","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4057","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters.","Type":"Description","Title":"CVE-2005-4057"},{"CveYear":"2005","CveId":"4057","Ordinal":"2","NoteData":"2005-12-07","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4057","Ordinal":"3","NoteData":"2005-12-12","Type":"Other","Title":"Modified"}]}}}