CVE-2005-1672 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 2.72% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ubertec | help center live |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities | 2004-05-17 |
References
→ the Explorer · watch your stack · NVD