CVE-2004-1827: XSS
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1827?
CVE-2004-1827 is considered a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2004-1827?
To fix CVE-2004-1827, users should upgrade to the latest version of YaBB or implement input sanitization to mitigate XSS risks.
What software is affected by CVE-2004-1827?
CVE-2004-1827 affects YaBB 1 Gold (SP1.3) and YaBB SE 1.5.1 Final, as well as certain versions of Simple Machines Forum.
What causes the vulnerability in CVE-2004-1827?
CVE-2004-1827 is caused by improper handling of the background:url property in glow and shadow tags, allowing script injection.
Who can exploit CVE-2004-1827?
Remote attackers can exploit CVE-2004-1827 to execute arbitrary web scripts in the context of the affected YaBB or SMF users.