{"api_version":"1","generated_at":"2026-07-23T03:41:37+00:00","cve":"CVE-2005-4285","urls":{"html":"https://cve.report/CVE-2005-4285","api":"https://cve.report/api/cve/CVE-2005-4285.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4285","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4285"},"summary":{"title":"CVE-2005-4285","description":"Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-16 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/15898","name":"http://www.securityfocus.com/bid/15898","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Dick Copits PDEstore Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/21727","name":"http://www.osvdb.org/21727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/18042","name":"http://secunia.com/advisories/18042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA18042 - PDEstore Cross-Site Scripting Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2912","name":"http://www.vupen.com/english/advisories/2005/2912","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: PDEstore XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4285","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4285","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4285","vulnerable":"1","versionEndIncluding":"1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dick_copits","cpe5":"pdestore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.466Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15898","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15898"},{"name":"21727","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21727"},{"name":"ADV-2005-2912","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2912"},{"name":"18042","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18042"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15898","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15898"},{"name":"21727","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21727"},{"name":"ADV-2005-2912","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2912"},{"name":"18042","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18042"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4285","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15898","refsource":"BID","url":"http://www.securityfocus.com/bid/15898"},{"name":"21727","refsource":"OSVDB","url":"http://www.osvdb.org/21727"},{"name":"ADV-2005-2912","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2912"},{"name":"18042","refsource":"SECUNIA","url":"http://secunia.com/advisories/18042"},{"name":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/pdestore-xss-vuln.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4285","datePublished":"2005-12-16T11:00:00.000Z","dateReserved":"2005-12-16T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.466Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-16 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dick_copits:pdestore:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8","matchCriteriaId":"49366601-B5AD-44DF-AB48-14A2534724F5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4285","Ordinal":"1","Title":"CVE-2005-4285","CVE":"CVE-2005-4285","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4285","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.","Type":"Description","Title":"CVE-2005-4285"},{"CveYear":"2005","CveId":"4285","Ordinal":"2","NoteData":"2005-12-16","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4285","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}