Back to search

CVE-2004-2115

MEDIUM
6.8NVD

Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.

CVSS v2.0 Score

6.8
/ 10.0
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P

Information

Published
31 déc. 2004
Updated
16 avr. 2026
Status
Modified
Source
cve@mitre.org

Affected products

Versions : 8.1.7, 9.0.1, 9.2.0

Weaknesses (CWE)

NVD-CWE-Other

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring