CVE-2005-1611
Description
WebCrossing WebX 5.x is vulnerable to XSS via specially crafted URLs, allowing script injection and potential cookie theft.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WebCrossing WebX 5.x is vulnerable to XSS via specially crafted URLs, allowing script injection and potential cookie theft.
Vulnerability
WebCrossing WebX version 5.x is susceptible to a cross-site scripting (XSS) vulnerability due to insufficient sanitization of user-supplied input. Attackers can inject arbitrary web script or HTML by including it in a URL after an "@" symbol [1].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL that includes arbitrary script code after the "@" character, such as http://www.example.com/webx?@[code]. This URL needs to be delivered to an unsuspecting user, typically through social engineering or by posting it on a website [1].
Impact
Successful exploitation allows an attacker to execute arbitrary script code within the context of the victim's browser. This can lead to the theft of sensitive information, such as cookie-based authentication credentials, and enable other client-side attacks [1].
Mitigation
Information regarding a fixed version or patch for this vulnerability is not yet disclosed in the available references. Users are advised to consult the vendor for potential workarounds or updates. This vulnerability is not listed on the KEV catalog.
AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:web_crossing_inc:web_crossing:5.x:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:web_crossing_inc:web_crossing:5.x:*:*:*:*:*:*:*
- (no CPE)range: 5.x
- Range: 5.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- osvdb.org/ref/16/16070-webcrossing.txtnvdExploitVendor Advisory
- secunia.com/advisories/15218nvdExploitVendor Advisory
- www.securityfocus.com/bid/13482nvdExploitVendor Advisory
- www.osvdb.org/16070nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/20381nvd
News mentions
0No linked articles in our index yet.