CVE-2005-4075
Last modified
CVE-2005-4075 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.. EPSS estimates a 1.88% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mycfnuke | Cf Nuke | <= 4.6 |
| Mycfnuke | Cf Nuke | 3.0a |
| Mycfnuke | Cf Nuke | 4.0 |
| Mycfnuke | Cf Nuke | 4.5 |
References
- http://secunia.com/advisories/17939Vendor Advisory
- http://secunia.com/advisories/17939Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4075?
How severe is CVE-2005-4075?
How do I fix CVE-2005-4075?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4069SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns…
- CVE-2005-4070Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-4071Multiple SQL injection vulnerabilities in CFMagic Magic Foru…
- CVE-2005-4072Cross-site scripting (XSS) vulnerability in CFMagic Magic Fo…
- CVE-2005-4073SQL injection vulnerability in view_archive.cfm in CFMagic M…
- CVE-2005-4074Directory traversal vulnerability in index.cfm in CF_Nuke 4.…
- CVE-2005-4076Buffer overflow in Appfluent Technology Database IDS 2.0 all…
- CVE-2005-4077Multiple off-by-one errors in the cURL library (libcurl) 7.1…
- CVE-2005-4078Multiple cross-site scripting (XSS) vulnerabilities in Ideal…
- CVE-2005-4079The register_globals emulation in phpMyAdmin 2.7.0 rc1 allow…
- CVE-2005-4080Horde IMP 4.0.4 and earlier does not sanitize strings contai…
- CVE-2005-4081Multiple SQL injection vulnerabilities in Alisveristr E-comm…
Are you affected by CVE-2005-4075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
