Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-05-10T04:00:00

Updated: 2021-04-29T14:37:14

Reserved: 2005-05-04T00:00:00


Link: CVE-2004-1863

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2004-12-31T05:00:00.000

Modified: 2021-04-29T15:15:09.473


Link: CVE-2004-1863

JSON object: View

cve-icon Redhat Information

No data.

CWE