CVE-2004-2028

E107 - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Chinchilla · textwebappsphp
https://www.exploit-db.com/exploits/24138

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11693
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6345
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108515632622796&w=2
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10395
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16231

Scores

EPSS 0.0066
EPSS Percentile 71.2%

Details

Status published
Products (11)
e107/e107 0.6_10
e107/e107 0.6_11
e107/e107 0.6_12
e107/e107 0.6_13
e107/e107 0.6_14
e107/e107 0.6_15
e107/e107 0.6_15a
e107/e107 0.545
e107/e107 0.554
e107/e107 0.555_beta
... and 1 more
Published May 21, 2004
Tracked Since Feb 18, 2026