4.3
CVSSv2

CVE-2004-2030

Published: 22/05/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay prior to 2.2.0 release 10/1/2004 allow remote malicious users to inject arbitrary web script or HTML, as demonstrated using the message subject.

Vulnerable Product Search on Vulmon Subscribe to Product

liferay liferay enterprise portal 2.1.0

liferay liferay enterprise portal

Exploits

source: wwwsecurityfocuscom/bid/10402/info It has been reported that Liferay Enterprise Portal is susceptible to multiple cross-site scripting and HTML injection vulnerabilities User-supplied data from many input fields is included in server generated content without appropriate validation/encoding This may allow for typical cross-site ...