CVE-2004-2656
Last modified
CVE-2004-2656 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Open Source Development Network | Slashcode | <= r_2_5_0_41 |
| Open Source Development Network | Slashcode | 2.2.5 |
References
- http://secunia.com/advisories/13491Patch, Vendor Advisory
- http://www.osvdb.org/21874Exploit, Patch
- http://www.osvdb.org/21875Exploit, Patch
- http://www.slashcode.com/slash/04/12/20/1946225.shtml?tid=11&tid=5&tid=4Patch, Vendor Advisory
- http://secunia.com/advisories/13491Patch, Vendor Advisory
- http://www.osvdb.org/21874Exploit, Patch
- http://www.osvdb.org/21875Exploit, Patch
- http://www.slashcode.com/slash/04/12/20/1946225.shtml?tid=11&tid=5&tid=4Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2656?
How severe is CVE-2004-2656?
How do I fix CVE-2004-2656?
Are you affected by CVE-2004-2656?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
