{"api_version":"1","generated_at":"2026-07-23T05:39:29+00:00","cve":"CVE-2004-1589","urls":{"html":"https://cve.report/CVE-2004-1589","api":"https://cve.report/api/cve/CVE-2004-1589.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1589","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1589"},"summary":{"title":"CVE-2004-1589","description":"Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17679","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17679","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11361","name":"http://www.securityfocus.com/bid/11361","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Go Smart Inc GoSmart Message Board Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12790/","name":"http://secunia.com/advisories/12790/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - GoSmart Message Board SQL Injection and Cross-Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=109751522823011&w=2","name":"http://marc.info/?l=bugtraq&m=109751522823011&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1589","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1589","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1589","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gosmart","cpe5":"gosmart_message_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:53:24.216Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"gosmart-forum-mainmessageid-xss(17679)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17679"},{"name":"20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109751522823011&w=2"},{"name":"11361","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11361"},{"name":"12790","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12790/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"gosmart-forum-mainmessageid-xss(17679)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17679"},{"name":"20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109751522823011&w=2"},{"name":"11361","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11361"},{"name":"12790","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12790/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1589","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"gosmart-forum-mainmessageid-xss(17679)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17679"},{"name":"20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109751522823011&w=2"},{"name":"11361","refsource":"BID","url":"http://www.securityfocus.com/bid/11361"},{"name":"12790","refsource":"SECUNIA","url":"http://secunia.com/advisories/12790/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1589","datePublished":"2005-02-20T05:00:00.000Z","dateReserved":"2005-02-20T00:00:00.000Z","dateUpdated":"2024-08-08T00:53:24.216Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gosmart:gosmart_message_board:*:*:*:*:*:*:*:*","matchCriteriaId":"957F8472-0B3A-4D20-8520-6370E1895F8F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1589","Ordinal":"1","Title":"CVE-2004-1589","CVE":"CVE-2004-1589","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1589","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.","Type":"Description","Title":"CVE-2004-1589"},{"CveYear":"2004","CveId":"1589","Ordinal":"2","NoteData":"2005-02-20","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1589","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}