4.3
CVSSv2

CVE-2004-1996

Published: 05/05/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote malicious users to inject arbitrary web script via the size tag.

Vulnerable Product Search on Vulmon Subscribe to Product

simple machines smf 1.0 beta4.1

simple machines smf 1.0 beta4p

simple machines smf 1.0 beta5p

Exploits

source: wwwsecurityfocuscom/bid/10281/info It has been reported that Simple Machines Forum (SMF) may be prone to an HTML injection vulnerability that may allow an attacker to execute arbitrary HTML or script code in a user's browser The issue exists due to insufficient sanitization of user-supplied input via the font size attribute Exp ...