4.3
CVSSv2

CVE-2004-2511

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.

Vulnerable Product Search on Vulmon Subscribe to Product

codeworx technologies dcp-portal 5.0.2

codeworx technologies dcp-portal 4.1

codeworx technologies dcp-portal 4.2

codeworx technologies dcp-portal

codeworx technologies dcp-portal 4.5.1

codeworx technologies dcp-portal 5.0.1

codeworx technologies dcp-portal 5.1

codeworx technologies dcp-portal 5.2

codeworx technologies dcp-portal 3.7

codeworx technologies dcp-portal 4.0

codeworx technologies dcp-portal 5.3

codeworx technologies dcp-portal 5.3.1

Exploits

source: wwwsecurityfocuscom/bid/11338/info DCP-Portal is reported prone to multiple cross-site scripting vulnerabilities It is reported that DCP-Portal does not sufficiently filter URI parameters supplied to several scripts Because of this deficiency, it is possible for a remote attacker to create a malicious link containing script c ...
source: wwwsecurityfocuscom/bid/11338/info DCP-Portal is reported prone to multiple cross-site scripting vulnerabilities It is reported that DCP-Portal does not sufficiently filter URI parameters supplied to several scripts Because of this deficiency, it is possible for a remote attacker to create a malicious link containing script c ...
source: wwwsecurityfocuscom/bid/11338/info DCP-Portal is reported prone to multiple cross-site scripting vulnerabilities It is reported that DCP-Portal does not sufficiently filter URI parameters supplied to several scripts Because of this deficiency, it is possible for a remote attacker to create a malicious link containing script cod ...