CVE-2004-2757: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.
Affected Software
5 affected components
Novell iChain<=2.2
Novell iChain<=2.2
Novell iChain<=2.2
Novell iChain<=2.2
Novell iChain<=2.2
Event History
Dec 31, 2004
CVE Published
05:00 AM
Nov 20, 2007
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2757?
CVE-2004-2757 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2004-2757?
To fix CVE-2004-2757, users should upgrade to Novell iChain version 2.2 build 2.2.113 or later.
3
What does CVE-2004-2757 affect?
CVE-2004-2757 affects Novell iChain versions prior to 2.2 build 2.2.113.
4
What type of attack is involved in CVE-2004-2757?
CVE-2004-2757 involves a cross-site scripting attack that allows remote attackers to inject scripts.
5
Can CVE-2004-2757 lead to data theft?
Yes, CVE-2004-2757 can lead to data theft by allowing attackers to execute malicious scripts in a user's browser.