CVE-2004-2402: XSS
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2402?
CVE-2004-2402 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-2402?
To fix CVE-2004-2402, upgrade to YaBB versions that do not contain this vulnerability or apply security patches provided by the vendor.
What versions of YaBB are affected by CVE-2004-2402?
CVE-2004-2402 affects YaBB 1 GOLD SP 1.3.2 and earlier versions.
What attack vectors are associated with CVE-2004-2402?
CVE-2004-2402 allows remote attackers to inject arbitrary web scripts or HTML through a vulnerable parameter.
Can CVE-2004-2402 be exploited by an attacker without authentication?
Yes, an attacker can exploit CVE-2004-2402 without requiring authentication, making it a potential risk for any YaBB instance.