CVE-2004-1996: XSS
Published May 5, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.
Affected Software
3 affected components
Simple Machines SMF=1.0_beta4.1
Simple Machines SMF=1.0_beta4p
Simple Machines SMF=1.0_beta5p
Event History
May 5, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1996?
CVE-2004-1996 has a moderate severity rating as it allows remote attackers to execute arbitrary web scripts via reflected XSS in the Simple Machines Forum.
2
How do I fix CVE-2004-1996?
To mitigate CVE-2004-1996, it is advised to upgrade to a patched version of Simple Machines Forum that addresses the XSS vulnerability.
3
Which versions of SMF are affected by CVE-2004-1996?
CVE-2004-1996 affects Simple Machines Forum versions 1.0_beta4.1, 1.0_beta4p, and 1.0_beta5p.
4
What type of vulnerability is CVE-2004-1996?
CVE-2004-1996 is classified as a Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2004-1996 be exploited remotely?
Yes, CVE-2004-1996 can be exploited remotely, allowing attackers to inject malicious scripts into web pages viewed by users.