CVE-2004-2725

Aztek Forum - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by benji lemien · textwebappsphp
https://www.exploit-db.com/exploits/24731

Scores

EPSS 0.0062
EPSS Percentile 69.7%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

aztek_forum/aztek_forum

Timeline

Published Dec 31, 2004
Tracked Since Feb 18, 2026