4.3
CVSSv2

CVE-2004-2756

Published: 31/12/2004 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 up to and including 2.0.5, allows remote malicious users to inject arbitrary web script or HTML via the (1) forum and (2) topic_id parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops 2.0

xoops xoops 2.0.5.2

xoops xoops 2.0.2

xoops xoops 2.0.5

xoops xoops 2.0.1

xoops xoops 2.0.3

xoops xoops 2.0.5.1

Exploits

source: wwwsecurityfocuscom/bid/9497/info It has been reported that Xoops may be prone to a cross-site scripting vulnerability that may allow a remote user to execute HTML or script code in a user's browser HTML and script code may be parsed via the 'topic_id' and 'forum' URI parameters of 'newbb/viewtopicphp' script Successful exploi ...