Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-2603

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2004-2603
Last Modified 07 Mar 2011 09:19:05
Published 31 Dec 2004 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2004-2603

Summary

Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

Vulnerable Systems

Application

  • Ubertec Help Center Live 1.0

  • Ubertec Help Center Live 1.2

  • Ubertec Help Center Live 1.2.1

  • Ubertec Help Center Live 1.2.2

  • Ubertec Help Center Live 1.2.3

  • Ubertec Help Center Live 1.2.4

  • Ubertec Help Center Live 1.2.5

  • Ubertec Help Center Live 1.2.6


References

XF - help-center-index-xss(18696)

BID - 12105

OSVDB - 12597

MISC - http://www.gulftech.org/?node=research&article_id=00058-12242004

SECTRACK - 1012685

SECUNIA - 13652


Last Updated: 27 May 2016 10:39:33