CVE-2004-2085
Summary
| CVE | CVE-2004-2085 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-02-04 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Brad Fears | Phpcodecabinet | 0.1 | All | All | All |
| Application | Brad Fears | Phpcodecabinet | 0.2 | All | All | All |
| Application | Brad Fears | Phpcodecabinet | 0.3 | All | All | All |
| Application | Brad Fears | Phpcodecabinet | 0.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/16711 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/3885 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Vendor Advisory |
| Brad Fears PHPCodeCabinet comments.php HTML Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| www.osvdb.org/3887 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SourceForge.net: File Release Notes and Changelog | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| phpCodeCabinet Input Validation Bugs Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| PHPCodeCabinet Multiple Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| www.osvdb.org/3886 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Patch, Vendor Advisory |
| cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | Vendor Advisory |
| Secunia - Advisories - phpCodeCabinet Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/16710 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.