4.3
CVSSv2

CVE-2004-1872

Published: 29/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote malicious users to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.

Vulnerable Product Search on Vulmon Subscribe to Product

webct webct campus_3.8

webct webct campus_3.8.4

webct webct campus_4.0

webct webct campus_4.1

webct webct campus_4.1.1.5

Exploits

source: wwwsecurityfocuscom/bid/9999/info It has been reported that WebCT Campus Edition may be prone to an HTML injection vulnerability that may allow a remote attacker to execute arbitrary HTML or script code in the browser of an unsuspecting user A malicious user could supply malicious HTML or script code to the application via the @i ...