Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Express-Web | Express-Web Content Management System | All versions |
References
- http://www.maxpatrol.com/advdetails.asp?id=12ExploitVendor Advisory
- http://www.maxpatrol.com/mp_advisory.asp
- http://www.securityfocus.com/bid/11426
- http://www.maxpatrol.com/advdetails.asp?id=12ExploitVendor Advisory
- http://www.maxpatrol.com/mp_advisory.asp
- http://www.securityfocus.com/bid/11426
FAQ
What is CVE-2004-2210?
CVE-2004-2210 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other ex...
How severe is CVE-2004-2210?
CVE-2004-2210 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2210?
Check the references section above for vendor advisories and patch information. Affected products include: Express-Web Express-Web Content Management System.