CVE-2004-2358: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in adminwords.php for phpBB 2.0.6c allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Affected Software
2 affected components
Phpbb Group Phpbb=2.0.6c
Phpbb Group Phpbb=2.0.6c
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2358?
CVE-2004-2358 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2004-2358?
To fix CVE-2004-2358, upgrade phpBB to a version later than 2.0.6c that does not have the XSS vulnerability.
3
What software is affected by CVE-2004-2358?
CVE-2004-2358 specifically affects phpBB version 2.0.6c.
4
What type of vulnerability is CVE-2004-2358?
CVE-2004-2358 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts.
5
Can CVE-2004-2358 impact my website's security?
Yes, if exploited, CVE-2004-2358 can compromise user data and site integrity by allowing malicious scripts to execute.