CVE-2004-2040: XSS

Published May 29, 2004
·
Updated

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN407 parameter to clockmenu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.

Affected Software

2 affected components
e107 e107=0.6_15
e107 e107=0.6_15a

Remediation

Event History

May 29, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2004-2040?

CVE-2004-2040 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.

2

How do I fix CVE-2004-2040?

To fix CVE-2004-2040, upgrade to a newer version of e107 that has addressed these cross-site scripting vulnerabilities.

3

What versions of e107 are affected by CVE-2004-2040?

CVE-2004-2040 affects e107 versions 0.6_15 and 0.6_15a.

4

What types of input are susceptible to CVE-2004-2040?

CVE-2004-2040 is vulnerable to XSS via the LAN_407 parameter in clock_menu.php, email article field, submit news field, and avmsg parameter in usersettings.php.

5

Can CVE-2004-2040 impact users' personal data?

Yes, CVE-2004-2040 can potentially impact users' personal data by allowing attackers to execute scripts that may steal sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203