CVE-2004-2076: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Affected Software
1 affected component
Jelsoft vBulletin=3.0.0_rc4
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2076?
CVE-2004-2076 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How does CVE-2004-2076 exploit work?
CVE-2004-2076 exploits a vulnerability in search.php allowing attackers to inject arbitrary web scripts or HTML via the query parameter.
3
Which software versions are affected by CVE-2004-2076?
CVE-2004-2076 affects Jelsoft vBulletin version 3.0.0 RC4.
4
How can I mitigate CVE-2004-2076?
To mitigate CVE-2004-2076, users should upgrade to a patched version of vBulletin that addresses the XSS vulnerability.
5
What are the risks associated with CVE-2004-2076?
The risks associated with CVE-2004-2076 include exposure to XSS attacks, which can lead to unauthorized access or data theft.