peter bassill · operator
$ cve CVE-2004-0672 JSON

CVE-2004-0672 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.01% — more likely to be exploited than 80% of all CVEs
On CISA KEVno
Public exploityes
Published2004-08-06
Last modified2026-06-16

Affected (2)

VendorProduct
netegrityidentityminder
netegritypolicy server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD