peter bassill · operator
$ cve CVE-2004-0358 JSON

CVE-2004-0358 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.2% (pctl 91)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.22% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
virtuasystemsvirtuanews pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD