First published: Sat Sep 18 2004(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo Open Source | =4.5_1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1692 has a medium severity level due to its potential for cross-site scripting attacks.
To fix CVE-2004-1692, you should upgrade to a version of Mambo that addresses this cross-site scripting vulnerability.
The affected parameters in CVE-2004-1692 are Itemid, mosmsg, and limit.
Any site running Mambo version 4.5 (1.0.9) is vulnerable to CVE-2004-1692.
CVE-2004-1692 can lead to cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.