CVE-2004-1809: XSS
Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1809?
CVE-2004-1809 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-1809?
To fix CVE-2004-1809, upgrade phpBB to version 2.0.7 or later where the vulnerability is patched.
What impact does CVE-2004-1809 have on web applications?
CVE-2004-1809 allows attackers to inject arbitrary HTML or script code into web pages viewed by other users, leading to potential data theft or session hijacking.
Which versions of phpBB are affected by CVE-2004-1809?
CVE-2004-1809 affects phpBB versions 2.0.6d and earlier.
Is CVE-2004-1809 still a concern for modern web applications?
CVE-2004-1809 is less of a concern today due to the age of the vulnerability and the widespread usage of updated phpBB versions.