CVE-2004-1863
Last modified
CVE-2004-1863 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.. EPSS estimates a 2.10% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmb Forum | Xmb | 1.8_sp3 |
| Xmb Forum | Xmb | 1.9_beta |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1863?
How severe is CVE-2004-1863?
How do I fix CVE-2004-1863?
Are you affected by CVE-2004-1863?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
