First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk Obsidian | =7.0 | |
Plesk Obsidian | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2702 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2004-2702, it is recommended to upgrade to a newer version of Plesk that has addressed this vulnerability.
CVE-2004-2702 affects users of Plesk versions 7.0 and 7.1 Reloaded.
Attackers can inject arbitrary web script or HTML into the login page, potentially compromising user credentials.
Yes, CVE-2004-2702 may be related to CVE-2006-6451, indicating a similar vulnerability vector.