CVE-2004-1645
Last modified
CVE-2004-1645 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.. EPSS estimates a 3.65% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jerod Moemeka | Xedus | 1.0 |
References
- http://secunia.com/advisories/12418Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/11071Exploit, Vendor Advisory
- http://secunia.com/advisories/12418Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/11071Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1645?
How severe is CVE-2004-1645?
How do I fix CVE-2004-1645?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1639Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913…
- CVE-2004-1640Multiple cross-site scripting (XSS) vulnerabilities in XOOPS…
- CVE-2004-1641Heap-based buffer overflow in Titan FTP 3.21 and earlier all…
- CVE-2004-1642WFTPD Pro Server 3.21 allows remote authenticated users to c…
- CVE-2004-1643WS_FTP 5.0.2 allows remote authenticated users to cause a de…
- CVE-2004-1644Xedus 1.0 allows remote attackers to cause a denial of servi…
- CVE-2004-1646Directory traversal vulnerability in Xedus 1.0 allows remote…
- CVE-2004-1647SQL injection vulnerability in Password Protect allows remot…
- CVE-2004-1648Cross-site scripting (XSS) vulnerability in (1) index.asp, (…
- CVE-2004-1649Buffer overflow in Microsoft Msinfo32.exe might allow local …
- CVE-2004-1650D-Link DCS-900 Internet Camera listens on UDP port 62976 for…
- CVE-2004-1651Multiple cross-site scripting (XSS) vulnerabilities in the r…
Are you affected by CVE-2004-1645?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
