VulnerabilityModified
CVE-2004-2720
Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.
MEDIUM 4.3EPSS 4.09%
Does this matter?
Lower severity and a low EPSS score (4.09%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.09% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- snitz communications/snitz forums 2000
- Source
- cve@mitre.org
References
- http://forum.snitz.com/forum/topic.asp?TOPIC_ID=53360
- http://secunia.com/advisories/11895Vendor Advisory
- http://securityreason.com/securityalert/3200
- http://securitytracker.com/id?1010524Patch
- http://www.osvdb.org/7190
- http://www.sec-tec.co.uk/vulnerability/snitzxss.html
- http://www.securityfocus.com/archive/1/366309Exploit
- http://www.securityfocus.com/bid/10564Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16444
- http://forum.snitz.com/forum/topic.asp?TOPIC_ID=53360
- http://secunia.com/advisories/11895Vendor Advisory
- http://securityreason.com/securityalert/3200
- http://securitytracker.com/id?1010524Patch
- http://www.osvdb.org/7190
- http://www.sec-tec.co.uk/vulnerability/snitzxss.html
- http://www.securityfocus.com/archive/1/366309Exploit
- http://www.securityfocus.com/bid/10564Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16444
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.