CVE-2004-1640
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.
- Affected products
- Xoops
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2005-02-20
CVE-2004-1640 at NVD
1 known exploit for CVE-2004-1640
Proof-of-concept code and exploit modules indexed by Sploitus