Unrated severityNVD Advisory· Published Aug 7, 2005· Updated Jun 16, 2026
CVE-2005-2488
CVE-2005-2488
Description
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- cpe:2.3:a:web_content_management:web_content_management_news_system:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- securitytracker.com/idnvdExploit
- www.rgod.altervista.org/webc.htmlnvdExploit
- secunia.com/advisories/16317nvdVendor Advisory
- www.securityfocus.com/bid/14464nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/21689nvd
News mentions
0No linked articles in our index yet.