CVE-2004-0339: XSS
Published Mar 18, 2004
·Updated
Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.
Affected Software
9 affected components
Phpbb Group Phpbb=2.0.5
Phpbb Group Phpbb=2.0.1
Phpbb Group Phpbb=2.0.3
Phpbb Group Phpbb=2.0
Phpbb Group Phpbb=2.0.4
Phpbb Group Phpbb=2.0.2
Phpbb Group Phpbb=2.0.6c
Phpbb Group Phpbb=2.0_rc4
Phpbb Group Phpbb=2.0.6
Remediation
Patch Available
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0339?
CVE-2004-0339 has a medium severity rating due to its ability to allow attackers to execute arbitrary scripts.
2
How do I fix CVE-2004-0339?
To fix CVE-2004-0339, upgrade phpBB to version 2.0.7 or later where the vulnerability has been addressed.
3
What versions of phpBB are affected by CVE-2004-0339?
CVE-2004-0339 affects phpBB versions 2.0.5 and earlier, including 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.6, and 2.0.6c.
4
What type of vulnerability is CVE-2004-0339?
CVE-2004-0339 is classified as a cross-site scripting (XSS) vulnerability.
5
What is the impact of exploiting CVE-2004-0339?
Exploiting CVE-2004-0339 allows attackers to execute arbitrary script or HTML as other users, leading to potential data theft or session hijacking.