Back

CVE-2005-0485

Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.

Published: Mar 30, 2005 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (1)

Vendor Product Version
phparena panews 2.0b4

GitHub Security Advisory GHSA-86q3-5fx8-mg6m

Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.83%

Top 23% most likely to be exploited

Threat Score 27.7 / 100

Data Sources

NVD EPSS GitHub