CVE Database
/

CVE-2005-1782

Back to search

CVE-2005-1782

Published: May 31, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

VendorProductVersions

n/a

n/a

affected
n/a

References

13783
vdb-entry
x_refsource_BID
1014058
vdb-entry
x_refsource_SECTRACK
16873
vdb-entry
x_refsource_OSVDB
16876
vdb-entry
x_refsource_OSVDB
16874
vdb-entry
x_refsource_OSVDB
16878
vdb-entry
x_refsource_OSVDB
16879
vdb-entry
x_refsource_OSVDB
16871
vdb-entry
x_refsource_OSVDB
16872
vdb-entry
x_refsource_OSVDB
16875
vdb-entry
x_refsource_OSVDB
16877
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now