CVE-2005-1440

N/A Unknown
Published: May 03, 2005 Modified: April 16, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://securitytracker.com/id?1013853
Source: cve@mitre.org
Exploit
http://www.osvdb.org/15951
Source: cve@mitre.org
Exploit Vendor Advisory
http://www.osvdb.org/15952
Source: cve@mitre.org
http://www.osvdb.org/15953
Source: cve@mitre.org
http://www.osvdb.org/15954
Source: cve@mitre.org
http://www.osvdb.org/15955
Source: cve@mitre.org
http://www.osvdb.org/15956
Source: cve@mitre.org
http://www.osvdb.org/15957
Source: cve@mitre.org
http://www.osvdb.org/15958
Source: cve@mitre.org
http://www.securityfocus.com/bid/13462
Source: cve@mitre.org
Exploit
http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://secunia.com/advisories/15181
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1013853
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/15951
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://www.osvdb.org/15952
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15953
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15954
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15955
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15956
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15957
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/15958
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/13462
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

24 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.7%
86th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

codetosell