{"api_version":"1","generated_at":"2026-07-23T06:09:06+00:00","cve":"CVE-2005-4489","urls":{"html":"https://cve.report/CVE-2005-4489","api":"https://cve.report/api/cve/CVE-2005-4489.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4489","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4489"},"summary":{"title":"CVE-2005-4489","description":"Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-22 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/21945","name":"http://www.osvdb.org/21945","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/3041","name":"http://www.vupen.com/english/advisories/2005/3041","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16014","name":"http://www.securityfocus.com/bid/16014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Scoop Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html","name":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Scoop XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18182","name":"http://secunia.com/advisories/18182","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Scoop Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21944","name":"http://www.osvdb.org/21944","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4489","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4489","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4489","vulnerable":"1","versionEndIncluding":"1.1_rc1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scoop","cpe5":"scoop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:05.293Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21945","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21945"},{"name":"16014","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16014"},{"name":"21944","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21944"},{"name":"ADV-2005-3041","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/3041"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html"},{"name":"18182","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18182"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21945","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21945"},{"name":"16014","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16014"},{"name":"21944","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21944"},{"name":"ADV-2005-3041","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/3041"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html"},{"name":"18182","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18182"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4489","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21945","refsource":"OSVDB","url":"http://www.osvdb.org/21945"},{"name":"16014","refsource":"BID","url":"http://www.securityfocus.com/bid/16014"},{"name":"21944","refsource":"OSVDB","url":"http://www.osvdb.org/21944"},{"name":"ADV-2005-3041","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/3041"},{"name":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/scoop-xss-vuln.html"},{"name":"18182","refsource":"SECUNIA","url":"http://secunia.com/advisories/18182"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4489","datePublished":"2005-12-22T11:00:00.000Z","dateReserved":"2005-12-22T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:05.293Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-22 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:scoop:scoop:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1_rc1","matchCriteriaId":"441E3572-21BF-47DB-898A-F77C5CC1D654"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4489","Ordinal":"1","Title":"CVE-2005-4489","CVE":"CVE-2005-4489","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4489","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.","Type":"Description","Title":"CVE-2005-4489"},{"CveYear":"2005","CveId":"4489","Ordinal":"2","NoteData":"2005-12-22","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4489","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}