CVE-2004-1823: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1823?
CVE-2004-1823 has a moderate severity level due to the potential for attackers to execute arbitrary scripts.
How do I fix CVE-2004-1823?
To fix CVE-2004-1823, update your vBulletin software to a version released after 3.0.0 or apply any available security patches.
What products are affected by CVE-2004-1823?
CVE-2004-1823 affects Jelsoft vBulletin versions 2.0 beta 3 up to 3.0, specifically 3.0.0 and 3.0.0_can4.
What kind of attacks can exploit CVE-2004-1823?
CVE-2004-1823 can be exploited through cross-site scripting (XSS) attacks allowing remote attackers to inject malicious scripts.
Is user data at risk due to CVE-2004-1823?
Yes, user data can be at risk due to potential XSS attacks which may lead to session hijacking or data theft.