CVE-2004-1872: XSS
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1872?
CVE-2004-1872 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-1872?
To address CVE-2004-1872, it is recommended to upgrade WebCT Campus Edition to the latest patched version.
What types of attacks can be performed using CVE-2004-1872?
CVE-2004-1872 allows remote attackers to execute arbitrary web scripts or HTML, potentially leading to session hijacking or data theft.
Which versions of WebCT are affected by CVE-2004-1872?
CVE-2004-1872 affects WebCT Campus Edition versions 4.0, 4.1, 3.8, and specifically 4.1.1.5.
How can I determine if my WebCT installation is vulnerable to CVE-2004-1872?
You can determine vulnerability to CVE-2004-1872 by checking the version of your WebCT Campus Edition against the affected versions.