First published: Fri Dec 31 2004(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | =1.9_beta | |
XMB Forum | =1.8_sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1863 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2004-1863, it is recommended to upgrade XMB to the latest version that addresses these XSS vulnerabilities.
CVE-2004-1863 includes attack vectors via the 'u2uheader' parameter in editprofile.php and multiple parameters in member.php, misc.php, and today.php.
Users of XMB version 1.9 beta and 1.8 SP3 are affected by CVE-2004-1863.
Exploiting CVE-2004-1863 can allow attackers to inject arbitrary web scripts or HTML into the affected XMB forums.