peter bassill · operator
$ cve CVE-2004-2522 JSON

CVE-2004-2522 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS4.01% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
geeos teamgattaca server 2003

Public exploits

SourceTitleDate
exploit-dbGattaca Server 2003 - Cross-Site Scripting2004-07-15

References

→ the Explorer  ·  watch your stack  ·  NVD