First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WHMCS | =campus_4.1_sp2_hotfix_40832 | |
WHMCS | =campus_4.0_sp3_hotfix_40833 | |
WHMCS | =campus_4.1 | |
WHMCS | =campus_4.1.1.5 | |
WHMCS | =campus_4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2015 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2004-2015, you should upgrade to the latest patched version of WebCT Campus Edition.
CVE-2004-2015 affects multiple versions of WebCT Campus Edition including 4.0, 4.0 SP3 Hotfix 40833, and 4.1.
CVE-2004-2015 allows attackers to inject arbitrary HTML or scripts through iframe, img, or object tags.
Users of WebCT Campus Edition who are using the vulnerable versions may be at risk of cross-site scripting attacks.