CVE-2004-2171: XSS
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2171?
CVE-2004-2171 is considered to have a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2004-2171?
To fix CVE-2004-2171, upgrade Cherokee to version 0.4.8 or higher, which includes patches for this vulnerability.
What software versions are affected by CVE-2004-2171?
CVE-2004-2171 affects Cherokee httpd versions 0.1, 0.1.5, 0.1.6, 0.2, 0.2.5, 0.2.6, 0.2.7, 0.4.6, and 0.4.7.
What type of vulnerability is CVE-2004-2171?
CVE-2004-2171 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
What impact can CVE-2004-2171 have on users?
Users exploited by CVE-2004-2171 could experience unauthorized actions performed on their behalf due to malicious scripts executed in their browser.