4.3

CVE-2004-2568

Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RecipantsRecipants Version1.0
RecipantsRecipants Version1.0.1
RecipantsRecipants Version1.1
RecipantsRecipants Version1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.635
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/11533
Patch
Vendor Advisory
http://securitytracker.com/id?1009984
Patch
http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415
Patch
http://www.securityfocus.com/bid/10250
Patch
http://www.osvdb.org/5787
Patch