Vulnerabilities > CVE-2004-1640
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
exploit available
Summary
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Nagl XOOPS Dictionary Module 1.0 Multiple Cross-Site Vulnerabilities. CVE-2004-1640. Webapps exploit for php platform |
id | EDB-ID:24415 |
last seen | 2016-02-02 |
modified | 2004-08-28 |
published | 2004-08-28 |
reporter | CyruxNET |
source | https://www.exploit-db.com/download/24415/ |
title | Nagl XOOPS Dictionary Module 1.0 - Multiple Cross-Site Vulnerabilities |
Nessus
NASL family | CGI abuses : XSS |
NASL id | XOOPS_DICTIONARY_XSS.NASL |
description | The remote version of XOOPS is vulnerable to several cross-site scripting attacks. An attacker can exploit it using the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14614 |
published | 2004-09-01 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14614 |
title | XOOPS <= 1.0 Dictionary Module Multiple Scripts XSS |
code |
|
References
- http://cyruxnet.org/modulo_dic_xoops.htm
- http://cyruxnet.org/modulo_dic_xoops.htm
- http://marc.info/?l=bugtraq&m=109394077209963&w=2
- http://marc.info/?l=bugtraq&m=109394077209963&w=2
- http://secunia.com/advisories/12424
- http://secunia.com/advisories/12424
- http://www.osvdb.org/9393
- http://www.osvdb.org/9393
- http://www.osvdb.org/9394
- http://www.osvdb.org/9394
- http://www.securityfocus.com/bid/11064
- http://www.securityfocus.com/bid/11064
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17152
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17152
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17154