CVE Vulnerabilities

CVE-2004-0358

Published: Nov 23, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Affected Software

Name Vendor Start Version End Version
Virtuanews_pro Virtuasystems 1.0 (including) 1.0 (including)
Virtuanews_pro Virtuasystems 1.0.1 (including) 1.0.1 (including)
Virtuanews_pro Virtuasystems 1.0.2 (including) 1.0.2 (including)
Virtuanews_pro Virtuasystems 1.0.3 (including) 1.0.3 (including)

References