CVE-2004-2756: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topicid parameters.
Affected Software
7 affected components
Xoops Xoops=2.0.5.1
Xoops Xoops=2.0.2
Xoops Xoops=2.0.5.2
Xoops Xoops=2.0.3
Xoops Xoops=2.0.1
Xoops Xoops=2.0
Xoops Xoops=2.0.5
Event History
Dec 31, 2004
CVE Published
05:00 AM
Nov 20, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2756?
The severity of CVE-2004-2756 is classified as medium due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2004-2756?
To fix CVE-2004-2756, it is recommended to upgrade to a newer version of Xoops that addresses this vulnerability.
3
What software is affected by CVE-2004-2756?
CVE-2004-2756 affects various versions of Xoops, including 2.0 through 2.0.5.2.
4
What are the attack vectors for CVE-2004-2756?
Attackers can exploit CVE-2004-2756 via the 'forum' and 'topic_id' parameters to inject malicious scripts or HTML.
5
Is CVE-2004-2756 still a threat today?
CVE-2004-2756 may still pose a threat to installations running affected versions of Xoops that are not updated.