4.3
CVSSv2

CVE-2004-1845

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

expinion.net news manager lite 2.5

Exploits

source: wwwsecurityfocuscom/bid/9935/info Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out SQL injection, cross-site scripting, and account hijacking attacks The issues exist in the 'comment_addasp', 'searchasp', 'category_news_headlineasp', 'moreasp', 'category_newsasp', an ...
source: wwwsecurityfocuscom/bid/9935/info Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out SQL injection, cross-site scripting, and account hijacking attacks The issues exist in the 'comment_addasp', 'searchasp', 'category_news_headlineasp', 'moreasp', 'category_newsasp', ...
source: wwwsecurityfocuscom/bid/9935/info Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out SQL injection, cross-site scripting, and account hijacking attacks The issues exist in the 'comment_addasp', 'searchasp', 'category_news_headlineasp', 'moreasp', 'category_newsasp', and ...