CVE-2005-3955

Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
References
Link Resource
http://retrogod.altervista.org/JAWS_062_sql.html
http://seclists.org/fulldisclosure/2015/May/35
http://secunia.com/advisories/17741 Patch Vendor Advisory
http://secunia.com/advisories/20842 Vendor Advisory
http://securitytracker.com/id?1015264
http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847 Patch
http://www.jaws-project.com/index.php?blog/show/29
http://www.osvdb.org/21112
http://www.osvdb.org/21113
http://www.osvdb.org/21643
http://www.securityfocus.com/archive/1/438434/100/0/threaded
http://www.securityfocus.com/bid/15555 Exploit
http://www.securityfocus.com/bid/18665
http://www.vupen.com/english/advisories/2006/2546 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27337
http://retrogod.altervista.org/JAWS_062_sql.html
http://seclists.org/fulldisclosure/2015/May/35
http://secunia.com/advisories/17741 Patch Vendor Advisory
http://secunia.com/advisories/20842 Vendor Advisory
http://securitytracker.com/id?1015264
http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847 Patch
http://www.jaws-project.com/index.php?blog/show/29
http://www.osvdb.org/21112
http://www.osvdb.org/21113
http://www.osvdb.org/21643
http://www.securityfocus.com/archive/1/438434/100/0/threaded
http://www.securityfocus.com/bid/15555 Exploit
http://www.securityfocus.com/bid/18665
http://www.vupen.com/english/advisories/2006/2546 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27337
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blogbuddies:blogbuddies:0.3:*:*:*:*:*:*:*
cpe:2.3:a:jaws:jaws:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:magpierss:magpierss:7.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://retrogod.altervista.org/JAWS_062_sql.html - () http://retrogod.altervista.org/JAWS_062_sql.html -
References () http://seclists.org/fulldisclosure/2015/May/35 - () http://seclists.org/fulldisclosure/2015/May/35 -
References () http://secunia.com/advisories/17741 - Patch, Vendor Advisory () http://secunia.com/advisories/17741 - Patch, Vendor Advisory
References () http://secunia.com/advisories/20842 - Vendor Advisory () http://secunia.com/advisories/20842 - Vendor Advisory
References () http://securitytracker.com/id?1015264 - () http://securitytracker.com/id?1015264 -
References () http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847 - Patch () http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847 - Patch
References () http://www.jaws-project.com/index.php?blog/show/29 - () http://www.jaws-project.com/index.php?blog/show/29 -
References () http://www.osvdb.org/21112 - () http://www.osvdb.org/21112 -
References () http://www.osvdb.org/21113 - () http://www.osvdb.org/21113 -
References () http://www.osvdb.org/21643 - () http://www.osvdb.org/21643 -
References () http://www.securityfocus.com/archive/1/438434/100/0/threaded - () http://www.securityfocus.com/archive/1/438434/100/0/threaded -
References () http://www.securityfocus.com/bid/15555 - Exploit () http://www.securityfocus.com/bid/15555 - Exploit
References () http://www.securityfocus.com/bid/18665 - () http://www.securityfocus.com/bid/18665 -
References () http://www.vupen.com/english/advisories/2006/2546 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2546 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27337 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27337 -

Information

Published : 2005-12-01 06:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-3955

Mitre link : CVE-2005-3955

CVE.ORG link : CVE-2005-3955


JSON object : View

Products Affected

jaws

  • jaws

blogbuddies

  • blogbuddies

magpierss

  • magpierss
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')