Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Jun 16, 2026
CVE-2005-4599
CVE-2005-4599
Description
Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:moxiecode:tinymce_compressor_php:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:moxiecode:tinymce_compressor_php:*:*:*:*:*:*:*:*range: <=1.05
- (no CPE)range: <1.06
Patches
Vulnerability mechanics
References
9- secunia.com/advisories/18262nvdPatchVendor Advisory
- tinymce.moxiecode.com/punbb/viewtopic.phpnvdPatch
- www.securityfocus.com/bid/16083nvdPatch
- www.hardened-php.net/advisory_262005.111.htmlnvdVendor Advisory
- securitytracker.com/idnvd
- tinymce.moxiecode.com/punbb/viewtopic.phpnvd
- www.osvdb.org/22117nvd
- www.securityfocus.com/archive/1/420543/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/23906nvd
News mentions
0No linked articles in our index yet.