CVE-2004-2030: XSS
Published May 22, 2004
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.
Affected Software
2 affected components
Liferay Liferay Enterprise Portal<=2.1.1
Liferay Liferay Enterprise Portal=2.1.0
Remediation
Patch Available
Patch Available
Event History
May 22, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2030?
CVE-2004-2030 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2004-2030?
To fix CVE-2004-2030, upgrade Liferay Enterprise Portal to version 2.2.0 or later.
3
What are the risks associated with CVE-2004-2030?
The risks include the potential for attackers to execute arbitrary scripts in the context of a user's browser.
4
Which versions of Liferay are affected by CVE-2004-2030?
CVE-2004-2030 affects Liferay Enterprise Portal versions prior to 2.2.0, specifically up to 2.1.1.
5
Can I mitigate CVE-2004-2030 without upgrading?
While the best practice is to upgrade, you may also implement input validation and sanitization to mitigate risks.