{"api_version":"1","generated_at":"2026-07-23T08:48:18+00:00","cve":"CVE-2005-4291","urls":{"html":"https://cve.report/CVE-2005-4291","api":"https://cve.report/api/cve/CVE-2005-4291.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4291","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4291"},"summary":{"title":"CVE-2005-4291","description":"Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-16 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/15891","name":"http://www.securityfocus.com/bid/15891","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"ECTOOLS Onlineshop Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html","name":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: ECTOOLS - Onlineshop XSS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2919","name":"http://www.vupen.com/english/advisories/2005/2919","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21731","name":"http://www.osvdb.org/21731","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/18028","name":"http://secunia.com/advisories/18028","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - ECTOOLS Onlineshop Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4291","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4291","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4291","vulnerable":"0","versionEndIncluding":"1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ectools","cpe5":"ectools_onlineshop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.556Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21731","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21731"},{"name":"ADV-2005-2919","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2919"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html"},{"name":"18028","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18028"},{"name":"15891","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15891"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21731","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21731"},{"name":"ADV-2005-2919","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2919"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html"},{"name":"18028","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18028"},{"name":"15891","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15891"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21731","refsource":"OSVDB","url":"http://www.osvdb.org/21731"},{"name":"ADV-2005-2919","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2919"},{"name":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/ectools-onlineshop-xss.html"},{"name":"18028","refsource":"SECUNIA","url":"http://secunia.com/advisories/18028"},{"name":"15891","refsource":"BID","url":"http://www.securityfocus.com/bid/15891"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4291","datePublished":"2005-12-16T11:00:00.000Z","dateReserved":"2005-12-16T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.556Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-16 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:ectools:ectools_onlineshop:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0","matchCriteriaId":"868B11E8-C9FF-4376-94F2-C2D4B24838F8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4291","Ordinal":"1","Title":"CVE-2005-4291","CVE":"CVE-2005-4291","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4291","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.","Type":"Description","Title":"CVE-2005-4291"},{"CveYear":"2005","CveId":"4291","Ordinal":"2","NoteData":"2005-12-16","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4291","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}