CVE-2004-2015: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.
Affected Software
5 affected components
WebCT WebCT=campus_4.1_sp2_hotfix_40832
WebCT WebCT=campus_4.0_sp3_hotfix_40833
WebCT WebCT=campus_4.1
WebCT WebCT=campus_4.1.1.5
WebCT WebCT=campus_4.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2015?
CVE-2004-2015 is classified as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2004-2015?
To fix CVE-2004-2015, you should upgrade to the latest patched version of WebCT Campus Edition.
3
What software versions are affected by CVE-2004-2015?
CVE-2004-2015 affects multiple versions of WebCT Campus Edition including 4.0, 4.0 SP3 Hotfix 40833, and 4.1.
4
What types of attacks can be executed due to CVE-2004-2015?
CVE-2004-2015 allows attackers to inject arbitrary HTML or scripts through iframe, img, or object tags.
5
Who is impacted by CVE-2004-2015?
Users of WebCT Campus Edition who are using the vulnerable versions may be at risk of cross-site scripting attacks.