4.3
CVSSv2

CVE-2004-1735

Published: 21/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and previous versions allows remote authenticated users to inject arbitrary web script or HTML via the description field.

Vulnerable Product Search on Vulmon Subscribe to Product

sympa sympa 4.1

sympa sympa 4.1.1

sympa sympa 4.1.2

sympa sympa 4.0

Exploits

source: wwwsecurityfocuscom/bid/10992/info An HTML injection vulnerability is reported in Sympa The problem occurs due to a failure of the application to properly sanitize user-supplied input data Unsuspecting users viewing the affected page will have attacker-supplied malicious code interpreted by their browser in the security context ...