CVE-2004-2288: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.
Affected Software
25 affected components
Jelsoft vBulletin=2.2.0
Jelsoft vBulletin=2.0_rc2
Jelsoft vBulletin=3.0_beta_6
Jelsoft vBulletin=2.3.0
Jelsoft vBulletin=2.3.2
Jelsoft vBulletin=2.0_rc3
Jelsoft vBulletin=2.2.1
Jelsoft vBulletin=2.2.7
Jelsoft vBulletin=2.0.3
Jelsoft vBulletin=3.0_beta_7
Jelsoft vBulletin=3.0_beta_3
Jelsoft vBulletin=2.2.4
Jelsoft vBulletin=3.0_beta_2
Jelsoft vBulletin=2.2.2
Jelsoft vBulletin=2.2.5
Jelsoft vBulletin=2.2.6
Jelsoft vBulletin=3.0_gamma
Jelsoft vBulletin=2.2.9
Jelsoft vBulletin=3.0_beta_4
Jelsoft vBulletin=1.0.1
Jelsoft vBulletin=2.2.8
Jelsoft vBulletin=2.3.4
Jelsoft vBulletin=2.2.3
Jelsoft vBulletin=3.0_beta_5
Jelsoft vBulletin=2.3.3
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 4, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2288?
CVE-2004-2288 is classified as a moderate severity vulnerability due to its potential to enable cross-site scripting attacks.
2
How does CVE-2004-2288 exploit work?
CVE-2004-2288 exploits the loc parameter in index.php of Jelsoft vBulletin, allowing attackers to inject malicious scripts.
3
How do I fix CVE-2004-2288?
To fix CVE-2004-2288, upgrade your vBulletin to the latest version that eliminates this vulnerability.
4
Which vBulletin versions are affected by CVE-2004-2288?
CVE-2004-2288 affects several versions of vBulletin, including 1.0.1 through 3.0_beta_7.
5
What can attackers achieve with CVE-2004-2288?
Attackers can use CVE-2004-2288 to spoof parts of a website, potentially leading to unauthorized actions taken on behalf of users.