← Back

CVE-2004-0322

nvd nist
Published: Feb 23, 2004Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.

Affected (3)

Products: Xmb Forum: Xmb
1 product
Xmb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Xmb Forum
Version 1.8
Version 1.8_sp1
Version 1.8_sp2

Timeline

No history available yet.