Back
CVE-2004-1716
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.
Published: Aug 16, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| powie | pforum | 1.24 |
| powie | pforum | 1.25 |
GitHub Security Advisory GHSA-3gx5-q8r9-268f
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject...
References (14)
- http://marc.info/?l=bugtraq&m=109267937212298&w=2
- http://secunia.com/advisories/12317/ Exploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/674542 Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/8985 Vendor Advisory
- http://www.pscript.de/news/index.php
- http://www.securityfocus.com/bid/10954 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17003
- http://marc.info/?l=bugtraq&m=109267937212298&w=2
- http://secunia.com/advisories/12317/ Exploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/674542 Exploit, Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/8985 Vendor Advisory
- http://www.pscript.de/news/index.php
- http://www.securityfocus.com/bid/10954 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17003
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
2.35%
Top 18% most likely to be exploited
Threat Score
27.9 / 100
Data Sources
NVD
EPSS
GitHub