CVE-2004-1692: XSS
Published Sep 18, 2004
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
Affected Software
1 affected component
Mambo Mambo Open Source=4.5_1.0.9
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 18, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1692?
CVE-2004-1692 has a medium severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2004-1692?
To fix CVE-2004-1692, you should upgrade to a version of Mambo that addresses this cross-site scripting vulnerability.
3
What are the affected parameters in CVE-2004-1692?
The affected parameters in CVE-2004-1692 are Itemid, mosmsg, and limit.
4
Who is vulnerable to CVE-2004-1692?
Any site running Mambo version 4.5 (1.0.9) is vulnerable to CVE-2004-1692.
5
What types of attacks can occur with CVE-2004-1692?
CVE-2004-1692 can lead to cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.