4.3
CVSSv2

CVE-2004-2514

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote malicious users to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.

Vulnerable Product Search on Vulmon Subscribe to Product

powerportal powerportal 1.1b

powerportal powerportal 1.3

powerportal powerportal 1.3b

Exploits

source: wwwsecurityfocuscom/bid/10835/info A vulnerability is reported for PowerPortal which may make it prone to HTML injection attacks The problem is said to occur due to a lack of sufficient sanitization performed on private message data Specifically, when creating PowerPortal private messages, the subject field may not be sufficien ...