Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.
References
Configurations
History
No history.
Information
Published : 2004-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-1845
Mitre link : CVE-2004-1845
CVE.ORG link : CVE-2004-1845
JSON object : View
Products Affected
expinion.net
- news_manager_lite
CWE