CVE-2004-0673 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.98% — more likely to be exploited than 80% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| simm-comm | sci photo chat |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SCI Photo Chat 3.4.9 - Cross-Site Scripting | 2004-07-20 |
References
→ the Explorer · watch your stack · NVD