4.3

CVE-2004-2017

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.75% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=108481571131866&w=2
http://secunia.com/advisories/11623
http://www.icefire.org/security/ttt-bugreport.txt
http://www.osvdb.org/6339
http://www.osvdb.org/6340
http://www.osvdb.org/6341
http://www.osvdb.org/6342
http://www.osvdb.org/6343
http://www.osvdb.org/6344
http://www.securityfocus.com/bid/10359
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16164