First published: Fri May 21 2004(Updated: )
Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.545 | |
e107 CMS | =0.554 | |
e107 CMS | =0.555_beta | |
e107 CMS | =0.603 | |
e107 CMS | =0.610 | |
e107 CMS | =0.611 | |
e107 CMS | =0.612 | |
e107 CMS | =0.613 | |
e107 CMS | =0.614 | |
e107 CMS | =0.615 | |
e107 CMS | =0.615a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2031 is considered a medium severity vulnerability.
To fix CVE-2004-2031, update e107 CMS to a version that is not affected by this vulnerability.
CVE-2004-2031 affects e107 CMS versions 0.545, 0.554, 0.555_beta, 0.603, 0.610, 0.611, 0.612, 0.613, 0.614, 0.615, and 0.615a.
CVE-2004-2031 facilitates cross-site scripting (XSS) attacks.
Users of the affected versions of e107 CMS are at risk of XSS vulnerabilities which can lead to data theft or site defacement.