VulnerabilityModified
CVE-2004-2072
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
MEDIUM 6.8EPSS 4.18%
Does this matter?
Lower severity and a low EPSS score (4.18%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.18% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- mambo/mambo open source
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/9588Exploit
- http://www.systemsecure.org/advisories/ssadvisory06022004.phpExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15062
- http://www.securityfocus.com/bid/9588Exploit
- http://www.systemsecure.org/advisories/ssadvisory06022004.phpExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15062
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.