{"api_version":"1","generated_at":"2026-07-23T04:28:22+00:00","cve":"CVE-2005-4237","urls":{"html":"https://cve.report/CVE-2005-4237","api":"https://cve.report/api/cve/CVE-2005-4237.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4237","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4237"},"summary":{"title":"CVE-2005-4237","description":"Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-14 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: MySQL Auction XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2876","name":"http://www.vupen.com/english/advisories/2005/2876","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18006","name":"http://secunia.com/advisories/18006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - MySQL Auction \"keyword\" Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15852","name":"http://www.securityfocus.com/bid/15852","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MySQL Auction Search Module Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/21685","name":"http://www.osvdb.org/21685","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4237","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4237","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4237","vulnerable":"1","versionEndIncluding":"3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"servers-r-us","cpe5":"mysqlauction","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.378Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21685","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21685"},{"name":"ADV-2005-2876","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2876"},{"name":"18006","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18006"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html"},{"name":"15852","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15852"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21685","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21685"},{"name":"ADV-2005-2876","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2876"},{"name":"18006","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18006"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html"},{"name":"15852","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15852"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4237","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21685","refsource":"OSVDB","url":"http://www.osvdb.org/21685"},{"name":"ADV-2005-2876","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2876"},{"name":"18006","refsource":"SECUNIA","url":"http://secunia.com/advisories/18006"},{"name":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/mysql-auction-xss-vuln.html"},{"name":"15852","refsource":"BID","url":"http://www.securityfocus.com/bid/15852"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4237","datePublished":"2005-12-14T11:00:00.000Z","dateReserved":"2005-12-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.378Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-14 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:servers-r-us:mysqlauction:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0","matchCriteriaId":"D7B04991-D039-4399-82D2-0516E2C60D2D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4237","Ordinal":"1","Title":"CVE-2005-4237","CVE":"CVE-2005-4237","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4237","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.","Type":"Description","Title":"CVE-2005-4237"},{"CveYear":"2005","CveId":"4237","Ordinal":"2","NoteData":"2005-12-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4237","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}