4.3

CVE-2004-2511

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.32% 0.916
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2004-10/0042.html
Exploit
http://secunia.com/advisories/12751
Vendor Advisory
Exploit
http://securitytracker.com/id?1006351
Exploit
http://www.osvdb.org/10585
Exploit
http://www.osvdb.org/10587
Exploit
http://www.osvdb.org/10588
Exploit
http://www.osvdb.org/10589
Exploit
http://www.osvdb.org/10590
Exploit
http://www.osvdb.org/11405
Exploit
http://www.securityfocus.com/bid/11338
Exploit
http://www.securityfocus.com/bid/11339
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/17638
https://exchange.xforce.ibmcloud.com/vulnerabilities/17639