CVE-2004-2325: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
Affected Software
10 affected components
DotNetNuke DotNetNuke=1.0.6
DotNetNuke DotNetNuke=1.0.7
DotNetNuke DotNetNuke=1.0.8
DotNetNuke DotNetNuke=1.0.9
DotNetNuke DotNetNuke=1.0.10d
dnnsoftware Dotnetnuke=1.0.6
dnnsoftware Dotnetnuke=1.0.7
dnnsoftware Dotnetnuke=1.0.8
dnnsoftware Dotnetnuke=1.0.9
dnnsoftware Dotnetnuke=1.0.10d
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2325?
CVE-2004-2325 is considered a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2004-2325?
To fix CVE-2004-2325, upgrade your DotNetNuke installation to version 1.0.11 or later.
3
What systems are affected by CVE-2004-2325?
CVE-2004-2325 affects DotNetNuke versions 1.0.6 through 1.0.10d.
4
What type of vulnerability is CVE-2004-2325?
CVE-2004-2325 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2004-2325 be exploited remotely?
Yes, CVE-2004-2325 can be exploited remotely by attackers to inject arbitrary script or HTML.