Back
CVE-2005-0485
Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.
Published: Mar 30, 2005
Modified: Jun 16, 2026
CWE-79
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| phparena | panews | 2.0b4 |
GitHub Security Advisory GHSA-86q3-5fx8-mg6m
Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows...
References (6)
- http://marc.info/?l=bugtraq&m=110863062605906&w=2 Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/12576 Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19359
- http://marc.info/?l=bugtraq&m=110863062605906&w=2 Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/12576 Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19359
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
1.83%
Top 23% most likely to be exploited
Threat Score
27.7 / 100
Data Sources
NVD
EPSS
GitHub