CVE-2005-1440
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.19%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html
- http://secunia.com/advisories/15181
- http://securitytracker.com/id?1013853
- http://www.osvdb.org/15951
- http://www.osvdb.org/15952
- http://www.osvdb.org/15953
- http://www.osvdb.org/15954
- http://www.osvdb.org/15955
- http://www.osvdb.org/15956
- http://www.osvdb.org/15957
- http://www.osvdb.org/15958
- http://www.securityfocus.com/bid/13462
- http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html
- http://secunia.com/advisories/15181
- http://securitytracker.com/id?1013853
- http://www.osvdb.org/15951
- http://www.osvdb.org/15952
- http://www.osvdb.org/15953
- http://www.osvdb.org/15954
- http://www.osvdb.org/15955
- http://www.osvdb.org/15956
- http://www.osvdb.org/15957
- http://www.osvdb.org/15958
- http://www.securityfocus.com/bid/13462
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-1440",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-05-03T04:00:00.000",
"references": [
{
"url": "http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/15181",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1013853",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15951",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15952",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15953",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15954",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15955",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15956",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15957",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/15958",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/13462",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/15181",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1013853",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15951",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15952",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15953",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15954",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15955",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15956",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15957",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/15958",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/13462",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php."
}
],
"lastModified": "2026-06-16T22:13:02.987",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:codetosell:viart_shop_enterprise:2.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F2746C9-9588-40F6-8B68-A05BB9A4B352"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}