VulnerabilityModified
CVE-2004-1589
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.
MEDIUM 4.3EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- gosmart/gosmart message board
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109751522823011&w=2
- http://secunia.com/advisories/12790/
- http://www.securityfocus.com/bid/11361Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17679
- http://marc.info/?l=bugtraq&m=109751522823011&w=2
- http://secunia.com/advisories/12790/
- http://www.securityfocus.com/bid/11361Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17679
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.