CVE-2005-1508
Last modified
CVE-2005-1508 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) id parameter to profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php, or (8) chaine_search, or (9) auteur_search parameter to the recherche module.. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) id parameter to profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php, or (8) chaine_search, or (9) auteur_search parameter to the recherche module.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pwsphp | Pwsphp | 1.2.2 |
References
- http://secunia.com/advisories/15315Vendor Advisory
- http://secunia.com/advisories/15315Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1508?
How severe is CVE-2005-1508?
How do I fix CVE-2005-1508?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1502Cross-site scripting (XSS) vulnerability in MidiCart PHP Sho…
- CVE-2005-1503Multiple SQL injection vulnerabilities in MidiCart PHP Shopp…
- CVE-2005-1504GameSpy SDK CD-Key Validation Toolkit, as used by many onlin…
- CVE-2005-1505The new account wizard in Mail.app 2.0 in Mac OS 10.4, when …
- CVE-2005-1506SQL injection vulnerability in out.php in CJ Ultra (CJUltra)…
- CVE-2005-1507Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and …
- CVE-2005-1509SQL injection vulnerability in profil.php in PwsPHP 1.2.2 al…
- CVE-2005-1510PwsPHP 1.2.2 allows remote attackers to obtain sensitive inf…
- CVE-2005-1511PwsPHP 1.2.2 allows remote attackers to bypass authenticatio…
- CVE-2005-1512The Admin panel in PwsPHP 1.2.2 does not properly verify upl…
- CVE-2005-1513Integer overflow in the stralloc_readyplus function in qmail…9.8
- CVE-2005-1514commands.c in qmail, when running on 64 bit platforms with a…
Are you affected by CVE-2005-1508?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
