CVE-2005-3085
UnknownEPSS 1.00%
Last modified
CVE-2005-3085 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Riverdark Studios | Rss Syndicator Module | 2.1.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3085?
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.
How severe is CVE-2005-3085?
Severity scoring for CVE-2005-3085 is pending analysis. The EPSS model estimates a 1.00% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3085?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3079PunBB before 1.2.8 allows remote attackers to perform "code …
- CVE-2005-3080contrib/example.php in GeSHi before 1.0.7.3 allows remote at…
- CVE-2005-3081wzdftpd 0.5.4 allows remote authenticated users to execute a…
- CVE-2005-3082SQL injection vulnerability in admin.php in SEO-Board 1.0.2 …
- CVE-2005-3083Cross-site scripting (XSS) vulnerability in index.php in CMS…
- CVE-2005-3084Buffer overflow in the TIFF library in the Photo Viewer for …
- CVE-2005-3086Directory traversal vulnerability in admin/about.php in cont…
- CVE-2005-3087The SecureW2 3.0 TLS implementation uses weak random number …
- CVE-2005-3088fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.…
- CVE-2005-3089Firefox 1.0.6 allows attackers to cause a denial of service …
- CVE-2005-3090Cross-site scripting (XSS) vulnerability in bug_actiongroup_…
- CVE-2005-3091Cross-site scripting (XSS) vulnerability in Mantis before 1.…
Are you affected by CVE-2005-3085?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
