CVE-2004-1544: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.
Affected Software
3 affected components
JSPWiki JSPWiki=2.1.121
JSPWiki JSPWiki=2.1.122
JSPWiki JSPWiki=2.1.120
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1544?
The severity of CVE-2004-1544 is considered to be medium, as it allows for cross-site scripting attacks.
2
Who is affected by CVE-2004-1544?
CVE-2004-1544 affects users of JSPWiki versions 2.1.120, 2.1.121, and 2.1.122.
3
How do I fix CVE-2004-1544?
To fix CVE-2004-1544, it is recommended to upgrade JSPWiki to a version later than 2.1.122.
4
What type of vulnerability is CVE-2004-1544?
CVE-2004-1544 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
What impact can CVE-2004-1544 have on users?
CVE-2004-1544 can allow attackers to execute arbitrary scripts in the context of other users, potentially leading to data theft or session hijacking.