CVE-2004-2030

Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_enterprise_portal:2.1.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=108526683823840&w=2 - () http://marc.info/?l=bugtraq&m=108526683823840&w=2 -
References () http://marc.info/?l=bugtraq&m=110141194202856&w=2 - () http://marc.info/?l=bugtraq&m=110141194202856&w=2 -
References () http://secunia.com/advisories/11692 - Vendor Advisory () http://secunia.com/advisories/11692 - Vendor Advisory
References () http://securitytracker.com/id?1010259 - () http://securitytracker.com/id?1010259 -
References () http://sourceforge.net/project/shownotes.php?release_id=252060 - () http://sourceforge.net/project/shownotes.php?release_id=252060 -
References () http://www.osvdb.org/6346 - Patch, Vendor Advisory () http://www.osvdb.org/6346 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/10402 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/10402 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16232 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16232 -

Information

Published : 2004-05-22 04:00

Updated : 2024-11-20 23:52


NVD link : CVE-2004-2030

Mitre link : CVE-2004-2030

CVE.ORG link : CVE-2004-2030


JSON object : View

Products Affected

liferay

  • liferay_enterprise_portal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')