{ "schema_version": "1.4.0", "id": "GHSA-7q22-c3mp-5f6r", "modified": "2022-05-01T02:19:10Z", "published": "2022-05-01T02:19:10Z", "aliases": [ "CVE-2005-3552" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-3552" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23003" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23004" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23006" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23007" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23008" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23009" }, { "type": "WEB", "url": "http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00110.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/17479" }, { "type": "WEB", "url": "http://securitytracker.com/id?1015167" }, { "type": "WEB", "url": "http://www.hardened-php.net/advisory_212005.80.html" }, { "type": "WEB", "url": "http://www.osvdb.org/20553" }, { "type": "WEB", "url": "http://www.osvdb.org/20554" }, { "type": "WEB", "url": "http://www.osvdb.org/20555" }, { "type": "WEB", "url": "http://www.osvdb.org/20556" }, { "type": "WEB", "url": "http://www.osvdb.org/20557" }, { "type": "WEB", "url": "http://www.osvdb.org/20558" }, { "type": "WEB", "url": "http://www.osvdb.org/20559" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/15354" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2005/2344" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2005-11-16T07:42:00Z" } }