{"api_version":"1","generated_at":"2026-07-23T09:29:50+00:00","cve":"CVE-2005-4373","urls":{"html":"https://cve.report/CVE-2005-4373","api":"https://cve.report/api/cve/CVE-2005-4373.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4373","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4373"},"summary":{"title":"CVE-2005-4373","description":"Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-20 02:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html","name":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: AWF (Adaptive Website Framework) vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21915","name":"http://www.osvdb.org/21915","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.awf-cms.org/news.html","name":"http://www.awf-cms.org/news.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AWF-CMS.org: News","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4373","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4373","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4373","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liquid_bytes_technologies","cpe5":"adaptive_website_framework","cpe6":"1.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4373","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liquid_bytes_technologies","cpe5":"adaptive_website_framework","cpe6":"2.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4373","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liquid_bytes_technologies","cpe5":"adaptive_website_framework","cpe6":"2.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4373","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liquid_bytes_technologies","cpe5":"adaptive_website_framework","cpe6":"2.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:04.290Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21915","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21915"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.awf-cms.org/news.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-01-04T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21915","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21915"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.awf-cms.org/news.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4373","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21915","refsource":"OSVDB","url":"http://www.osvdb.org/21915"},{"name":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/awf-adaptive-website-framework-vuln.html"},{"name":"http://www.awf-cms.org/news.html","refsource":"CONFIRM","url":"http://www.awf-cms.org/news.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4373","datePublished":"2005-12-20T02:00:00.000Z","dateReserved":"2005-12-20T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:04.290Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-20 02:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:liquid_bytes_technologies:adaptive_website_framework:1.11:*:*:*:*:*:*:*","matchCriteriaId":"9EF74DAD-E978-4797-98A8-64A9874DEE39"},{"vulnerable":false,"criteria":"cpe:2.3:a:liquid_bytes_technologies:adaptive_website_framework:2.00:*:*:*:*:*:*:*","matchCriteriaId":"4EE068EB-D6B3-4222-8710-F4A0949C9BDB"},{"vulnerable":false,"criteria":"cpe:2.3:a:liquid_bytes_technologies:adaptive_website_framework:2.01:*:*:*:*:*:*:*","matchCriteriaId":"26D3ED9E-98FF-4D11-AAB2-F00A7E5F1AE4"},{"vulnerable":false,"criteria":"cpe:2.3:a:liquid_bytes_technologies:adaptive_website_framework:2.10:*:*:*:*:*:*:*","matchCriteriaId":"A72D1A2A-6A50-4AA2-BC1E-EED9A6588573"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4373","Ordinal":"1","Title":"CVE-2005-4373","CVE":"CVE-2005-4373","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4373","Ordinal":"1","NoteData":"Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.","Type":"Description","Title":"CVE-2005-4373"},{"CveYear":"2005","CveId":"4373","Ordinal":"2","NoteData":"2005-12-19","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4373","Ordinal":"3","NoteData":"2006-01-04","Type":"Other","Title":"Modified"}]}}}