Lucene search

K
cveMitreCVE-2004-0660
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0660

2004-08-0604:00:00
mitre
web.nvd.nist.gov
43
cve
2004
0660
cross-site scripting
xss
cutenews
php files

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.9

Confidence

High

EPSS

0.008

Percentile

82.0%

Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.

Affected configurations

Nvd
Node
cutephpcutenewsMatch0.88
OR
cutephpcutenewsMatch1.3
OR
cutephpcutenewsMatch1.3.1
VendorProductVersionCPE
cutephpcutenews0.88cpe:2.3:a:cutephp:cutenews:0.88:*:*:*:*:*:*:*
cutephpcutenews1.3cpe:2.3:a:cutephp:cutenews:1.3:*:*:*:*:*:*:*
cutephpcutenews1.3.1cpe:2.3:a:cutephp:cutenews:1.3.1:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.9

Confidence

High

EPSS

0.008

Percentile

82.0%

Related for CVE-2004-0660