First published: Sat Aug 28 2004(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Xoops Dictionary | =1.0 | |
Xoops Xoops Dictionary | =0.94 | |
Xoops Xoops Dictionary | =0.94 | |
Xoops Xoops Dictionary | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1640 has a moderate severity level due to its potential to execute arbitrary scripts.
To fix CVE-2004-1640, upgrade to a non-vulnerable version of XOOPS, specifically versions later than 1.0.
Versions 0.94 and 1.0 of XOOPS are affected by CVE-2004-1640.
CVE-2004-1640 can be exploited via the terme parameter in search.php and the letter parameter in letter.php.
Yes, if exploited, CVE-2004-1640 can enable attackers to execute scripts that potentially steal user information.