CVE-2004-1655: XSS
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CMpid parameter in the comments module or (2) the subject or message fields in the notes module.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1655?
CVE-2004-1655 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2004-1655?
To fix CVE-2004-1655, it is recommended to upgrade phpWebsite to a version later than 0.9.3-4.
What software versions are affected by CVE-2004-1655?
CVE-2004-1655 affects phpWebsite versions 0.9.3-4 and earlier, including 0.9.3, 0.8.3, 0.8.2, and 0.7.3.
What types of attacks can be executed due to CVE-2004-1655?
CVE-2004-1655 can allow attackers to execute arbitrary web scripts or HTML, leading to potential data theft or session hijacking.
Is CVE-2004-1655 a common vulnerability?
CVE-2004-1655 identifies a known cross-site scripting vulnerability that has been addressed in later versions of phpWebsite.