Vulnerabilities > CVE-2004-0271 - Input Validation vulnerability in Maxwebportal 1.30/1.31

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
maxwebportal
exploit available

Summary

Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form. This vulnerability is addressed in the following product release: MaxWebPortal, MaxWebPortal, 1.32

Vulnerable Configurations

Part Description Count
Application
Maxwebportal
2

Exploit-Db

  • descriptionMaxWebPortal 1.3x Personal Message SendTo Parameter XSS. CVE-2004-0271. Webapps exploit for asp platform
    idEDB-ID:23677
    last seen2016-02-02
    modified2004-02-10
    published2004-02-10
    reporterManuel Lopez
    sourcehttps://www.exploit-db.com/download/23677/
    titleMaxWebPortal 1.3x Personal Message SendTo Parameter XSS
  • descriptionMaxWebPortal 1.3x down.asp HTTP_REFERER XSS. CVE-2004-0271. Webapps exploit for asp platform
    idEDB-ID:23676
    last seen2016-02-02
    modified2004-02-10
    published2004-02-10
    reporterManuel Lopez
    sourcehttps://www.exploit-db.com/download/23676/
    titleMaxWebPortal 1.3x down.asp HTTP_REFERER XSS