{"api_version":"1","generated_at":"2026-07-23T10:20:51+00:00","cve":"CVE-2005-4488","urls":{"html":"https://cve.report/CVE-2005-4488","api":"https://cve.report/api/cve/CVE-2005-4488.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4488","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4488"},"summary":{"title":"CVE-2005-4488","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-22 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2005/3038","name":"http://www.vupen.com/english/advisories/2005/3038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18195","name":"http://secunia.com/advisories/18195","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Redakto WCMS Cross-Site Scripting Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Redakto WCMS multiple XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16013","name":"http://www.securityfocus.com/bid/16013","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"ComputerOil Redakto CMS Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4488","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4488","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4488","vulnerable":"1","versionEndIncluding":"3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"computeroil","cpe5":"redakto_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:05.508Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2005-3038","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/3038"},{"name":"18195","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18195"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html"},{"name":"16013","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16013"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2005-3038","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/3038"},{"name":"18195","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18195"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html"},{"name":"16013","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16013"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4488","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2005-3038","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/3038"},{"name":"18195","refsource":"SECUNIA","url":"http://secunia.com/advisories/18195"},{"name":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/redakto-wcms-multiple-xss-vuln.html"},{"name":"16013","refsource":"BID","url":"http://www.securityfocus.com/bid/16013"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4488","datePublished":"2005-12-22T11:00:00.000Z","dateReserved":"2005-12-22T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:05.508Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-22 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:computeroil:redakto_cms:*:*:*:*:*:*:*:*","versionEndIncluding":"3.2","matchCriteriaId":"E1A83ABF-F5CF-457D-9047-426A124710F9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4488","Ordinal":"1","Title":"CVE-2005-4488","CVE":"CVE-2005-4488","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4488","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.","Type":"Description","Title":"CVE-2005-4488"},{"CveYear":"2005","CveId":"4488","Ordinal":"2","NoteData":"2005-12-22","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4488","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}