Lucene search

K
cveMitreCVE-2004-1862
HistoryMay 10, 2005 - 4:00 a.m.

CVE-2004-1862

2005-05-1004:00:00
mitre
web.nvd.nist.gov
34
cve
2004
1862
xss
vulnerabilities
extreme messageboard
xmb
remote attackers
web script
html
injection

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.015

Percentile

87.1%

Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.

Affected configurations

Nvd
Node
xmb_forumxmbMatch1.8_sp3
OR
xmb_forumxmbMatch1.9_beta
VendorProductVersionCPE
xmb_forumxmb1.8_sp3cpe:2.3:a:xmb_forum:xmb:1.8_sp3:*:*:*:*:*:*:*
xmb_forumxmb1.9_betacpe:2.3:a:xmb_forum:xmb:1.9_beta:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.015

Percentile

87.1%

Related for CVE-2004-1862