CVE-2004-2038

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:neocrome:land_down_under:*:*:*:*:*:*:*:*
cpe:2.3:a:neocrome:land_down_under:601:*:*:*:*:*:*:*
cpe:2.3:a:neocrome:land_down_under:602:*:*:*:*:*:*:*
cpe:2.3:a:neocrome:land_down_under:700.01:*:*:*:*:*:*:*
cpe:2.3:a:neocrome:land_down_under:700.02:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://ldu.neocrome.net/page.php?id=1357 - () http://ldu.neocrome.net/page.php?id=1357 -
References () http://marc.info/?l=bugtraq&m=108585789220174&w=2 - () http://marc.info/?l=bugtraq&m=108585789220174&w=2 -
References () http://secunia.com/advisories/11739 - Patch, Vendor Advisory () http://secunia.com/advisories/11739 - Patch, Vendor Advisory
References () http://securitytracker.com/alerts/2004/May/1010335.html - () http://securitytracker.com/alerts/2004/May/1010335.html -
References () http://www.osvdb.org/6508 - Patch, Vendor Advisory () http://www.osvdb.org/6508 - Patch, Vendor Advisory
References () http://www.osvdb.org/6510 - Patch, Vendor Advisory () http://www.osvdb.org/6510 - Patch, Vendor Advisory
References () http://www.osvdb.org/6511 - Patch, Vendor Advisory () http://www.osvdb.org/6511 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/10435 - () http://www.securityfocus.com/bid/10435 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16284 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16284 -

Information

Published : 2004-05-29 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2004-2038

Mitre link : CVE-2004-2038

CVE.ORG link : CVE-2004-2038


JSON object : View

Products Affected

neocrome

  • land_down_under