Unrated severityNVD Advisory· Published Nov 1, 2005· Updated Apr 16, 2026
CVE-2005-3403
CVE-2005-3403
Description
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) the p parameter in add_note.php.
Affected products
5cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.4.1:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.5.1_pl1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/16915/nvdPatchVendor Advisory
- secunia.com/secunia_research/2005-55/advisory/nvdPatchVendor Advisory
- www.osvdb.org/20347nvdPatch
- www.osvdb.org/20348nvdPatch
- www.osvdb.org/20349nvdPatch
- www.securityfocus.com/bid/15221nvdExploitPatch
- atutor.ca/view/3/6158/1.htmlnvd
- marc.infonvd
- securityreason.com/securityalert/123nvd
- securitytracker.com/idnvd
- www.vupen.com/english/advisories/2005/2228nvd
News mentions
0No linked articles in our index yet.