VYPR
Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Apr 16, 2026

CVE-2005-2467

CVE-2005-2467

Description

Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.

Affected products

8
  • MySQL/Eventum8 versions
    cpe:2.3:a:mysql:eventum:1.1:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:mysql:eventum:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mysql:eventum:1.5.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.