CVE Vulnerabilities

CVE-2004-2040

Published: May 29, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) email article to a friend field, (3) submit news field, or (4) avmsg parameter to usersettings.php.

Affected Software

Name Vendor Start Version End Version
E107 E107 0.6_15 (including) 0.6_15 (including)
E107 E107 0.6_15a (including) 0.6_15a (including)

References