{
    "id": "CVE-2005-1782",
    "published": "2005-05-26 04:00:00",
    "last_modified": "2026-06-16 22:13:40",
    "cvss_score": "4.3",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
    "cwe": null,
    "description": "Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.",
    "epss_score": "0.05130",
    "epss_percentile": "0.92141",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-02 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "w.m.r._simpson",
            "product": "bookreview"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "25727",
            "title": "BookReview 1.0 - 'add_review.htm' Multiple Cross-Site Scripting Vulnerabilities",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25727"
        },
        {
            "source": "exploit-db",
            "ref_id": "25728",
            "title": "BookReview 1.0 - 'add_contents.htm' Multiple Cross-Site Scripting Vulnerabilities",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25728"
        },
        {
            "source": "exploit-db",
            "ref_id": "25729",
            "title": "BookReview 1.0 - 'suggest_category.htm?node' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25729"
        },
        {
            "source": "exploit-db",
            "ref_id": "25730",
            "title": "BookReview 1.0 - 'contact.htm?user' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25730"
        },
        {
            "source": "exploit-db",
            "ref_id": "25731",
            "title": "BookReview 1.0 - 'add_booklist.htm?node' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25731"
        },
        {
            "source": "exploit-db",
            "ref_id": "25732",
            "title": "BookReview 1.0 - 'add_url.htm?node' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25732"
        },
        {
            "source": "exploit-db",
            "ref_id": "25733",
            "title": "BookReview 1.0 - 'search.htm?submit string' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25733"
        },
        {
            "source": "exploit-db",
            "ref_id": "25734",
            "title": "BookReview 1.0 - 'add_classification.htm?isbn' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25734"
        },
        {
            "source": "exploit-db",
            "ref_id": "25735",
            "title": "BookReview 1.0 - 'suggest_review.htm?node' Cross-Site Scripting",
            "date": "2005-05-26",
            "url": "https://www.exploit-db.com/exploits/25735"
        }
    ],
    "refs_list": [
        "http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html",
        "http://securitytracker.com/id?1014058",
        "http://www.osvdb.org/16871",
        "http://www.osvdb.org/16872",
        "http://www.osvdb.org/16873",
        "http://www.osvdb.org/16874",
        "http://www.osvdb.org/16875",
        "http://www.osvdb.org/16876",
        "http://www.osvdb.org/16877",
        "http://www.osvdb.org/16878",
        "http://www.osvdb.org/16879",
        "http://www.securityfocus.com/bid/13783",
        "http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html",
        "http://securitytracker.com/id?1014058",
        "http://www.osvdb.org/16871",
        "http://www.osvdb.org/16872",
        "http://www.osvdb.org/16873",
        "http://www.osvdb.org/16874",
        "http://www.osvdb.org/16875",
        "http://www.osvdb.org/16876",
        "http://www.osvdb.org/16877",
        "http://www.osvdb.org/16878",
        "http://www.osvdb.org/16879",
        "http://www.securityfocus.com/bid/13783"
    ]
}