Vulnerabilities > CVE-2004-1823 - Cross-Site Scripting vulnerability in Jelsoft Vbulletin 3.0.0/3.0.0Can4
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description VBulletin 3.0 ShowThread.PHP Cross-Site Scripting Vulnerability. CVE-2004-1823. Webapps exploit for php platform id EDB-ID:23823 last seen 2016-02-02 modified 2004-03-16 published 2004-03-16 reporter JeiAr source https://www.exploit-db.com/download/23823/ title VBulletin 3.0 ShowThread.PHP Cross-Site Scripting Vulnerability description VBulletin 3.0 ForumDisplay.PHP Cross-Site Scripting Vulnerability. CVE-2004-1823. Webapps exploit for php platform id EDB-ID:23822 last seen 2016-02-02 modified 2004-03-16 published 2004-03-16 reporter JeiAr source https://www.exploit-db.com/download/23822/ title VBulletin 3.0 ForumDisplay.PHP Cross-Site Scripting Vulnerability
References
- http://marc.info/?l=bugtraq&m=107945556112453&w=2
- http://secunia.com/advisories/11142
- http://securitytracker.com/id?1009440
- http://www.osvdb.org/4310
- http://www.osvdb.org/4311
- http://www.securityfocus.com/bid/9888
- http://www.securityfocus.com/bid/9889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15495