Vulnerability Description
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arbitroweb | Arbitroweb | 0.5 |
References
- http://marc.info/?l=bugtraq&m=108794392303244&w=2
- http://www.securityfocus.com/bid/10592Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16481
- http://marc.info/?l=bugtraq&m=108794392303244&w=2
- http://www.securityfocus.com/bid/10592Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16481
FAQ
What is CVE-2004-0617?
CVE-2004-0617 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.
How severe is CVE-2004-0617?
CVE-2004-0617 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0617?
Check the references section above for vendor advisories and patch information. Affected products include: Arbitroweb Arbitroweb.