CVE-2004-2702

Swsoft Plesk - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

Exploits (1)

exploitdb WORKING POC VERIFIED
by sourvivor · textwebappsphp
https://www.exploit-db.com/exploits/24405

Scores

EPSS 0.0767
EPSS Percentile 91.8%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

swsoft/plesk
swsoft/plesk

Timeline

Published Dec 31, 2004
Tracked Since Feb 18, 2026