CVE-2004-1640

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xoops:xoops_dictionary:0.94:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops_dictionary:1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:51

Type Values Removed Values Added
References () http://cyruxnet.org/modulo_dic_xoops.htm - () http://cyruxnet.org/modulo_dic_xoops.htm -
References () http://marc.info/?l=bugtraq&m=109394077209963&w=2 - () http://marc.info/?l=bugtraq&m=109394077209963&w=2 -
References () http://secunia.com/advisories/12424 - Vendor Advisory () http://secunia.com/advisories/12424 - Vendor Advisory
References () http://www.osvdb.org/9393 - () http://www.osvdb.org/9393 -
References () http://www.osvdb.org/9394 - () http://www.osvdb.org/9394 -
References () http://www.securityfocus.com/bid/11064 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/11064 - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17152 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17152 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17154 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17154 -

Information

Published : 2004-08-28 04:00

Updated : 2024-11-20 23:51


NVD link : CVE-2004-1640

Mitre link : CVE-2004-1640

CVE.ORG link : CVE-2004-1640


JSON object : View

Products Affected

xoops

  • xoops_dictionary