CVE-2004-0310

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/11/2004
Last modified:
11/07/2017

Description

Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:livejournal:livejournal:*:*:*:*:*:*:*:*