Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1442
CVE-2004-1442
Description
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/9488nvdExploit
- www.kb.cert.org/vuls/id/197318nvdThird Party AdvisoryUS Government Resource
- www.kb.cert.org/vuls/id/DMOA-5VNPELnvdThird Party AdvisoryUS Government Resource
- archives.neohapsis.com/archives/vulnwatch/2004-q1/0019.htmlnvd
- secunia.com/advisories/10709/nvd
- secunia.com/secunia_research/2004-1/advisory/nvd
- www.osvdb.org/3712nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/14925nvd
News mentions
0No linked articles in our index yet.