Vulnerabilities > CVE-2004-0358 - Module Cross-Site Scripting vulnerability in VirtuaSystems VirtuaNews

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
virtuasystems
exploit available

Summary

Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Exploit-Db

descriptionVirtuaSystems VirtuaNews 1.0.x Multiple Module Cross-Site Scripting Vulnerabilities. CVE-2004-0358. Webapps exploit for php platform
idEDB-ID:23792
last seen2016-02-02
modified2004-03-05
published2004-03-05
reporterRafel Ivgi The-Insider
sourcehttps://www.exploit-db.com/download/23792/
titleVirtuaSystems VirtuaNews 1.0.x - Multiple Module Cross-Site Scripting Vulnerabilities