Vulnerability Details CVE-2004-2756
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topic_id parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2004-2756
-
cpe:2.3:a:xoops:xoops:2.0
-
cpe:2.3:a:xoops:xoops:2.0.1
-
cpe:2.3:a:xoops:xoops:2.0.2
-
cpe:2.3:a:xoops:xoops:2.0.3
-
cpe:2.3:a:xoops:xoops:2.0.5
-
cpe:2.3:a:xoops:xoops:2.0.5.1
-
cpe:2.3:a:xoops:xoops:2.0.5.2