Vulnerabilities > CVE-2004-1827
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
Application | 1 |
Exploit-Db
description | YABB SE 1.5.1 Multiple Cross-Site Scripting Vulnerabilites. CVE-2004-1827. Webapps exploit for php platform |
id | EDB-ID:23812 |
last seen | 2016-02-02 |
modified | 2004-03-15 |
published | 2004-03-15 |
reporter | Cheng Peng Su |
source | https://www.exploit-db.com/download/23812/ |
title | YABB SE 1.5.1 - Multiple Cross-Site Scripting Vulnerabilites |
References
- http://marc.info/?l=bugtraq&m=107936800226430&w=2
- http://marc.info/?l=bugtraq&m=107936800226430&w=2
- http://marc.info/?l=bugtraq&m=107948064923981&w=2
- http://marc.info/?l=bugtraq&m=107948064923981&w=2
- http://secunia.com/advisories/11128
- http://secunia.com/advisories/11128
- http://securitytracker.com/id?1009427
- http://securitytracker.com/id?1009427
- http://www.securityfocus.com/bid/9873
- http://www.securityfocus.com/bid/9873
- http://www.yabbforum.com/community/YaBB.pl?board=general%3Baction=display%3Bnum=1093133233
- http://www.yabbforum.com/community/YaBB.pl?board=general%3Baction=display%3Bnum=1093133233
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15488
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15488