CVE-2005-1403

N/A Unknown
Published: May 03, 2005 Modified: April 16, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/15155
Source: cve@mitre.org
Exploit Vendor Advisory
http://securitytracker.com/id?1013836
Source: cve@mitre.org
Exploit
http://www.osvdb.org/15892
Source: cve@mitre.org
http://www.osvdb.org/15893
Source: cve@mitre.org
http://www.osvdb.org/15894
Source: cve@mitre.org
Exploit Vendor Advisory
http://www.securityfocus.com/bid/13427
Source: cve@mitre.org
Exploit
http://lostmon.blogspot.com/2005/04/amazon-webstore-script-injection-and.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://secunia.com/advisories/15155
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://securitytracker.com/id?1013836
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/15892
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15893
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15894
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://www.securityfocus.com/bid/13419
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/13425
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/13426
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/13427
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

20 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.9%
83th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

just_williams