4.3
CVE-2004-1659
- EPSS 3.59%
- Veröffentlicht 02.09.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:08:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.59% | 0.879 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/12432
http://marc.info/?l=bugtraq&m=109415338521881&w=2
http://www.securityfocus.com/bid/11097
https://exchange.xforce.ibmcloud.com/vulnerabilities/17214