VYPR
Unrated severityNVD Advisory· Published May 29, 2004· Updated Apr 16, 2026

CVE-2004-2038

CVE-2004-2038

Description

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.

Affected products

5
  • cpe:2.3:a:neocrome:land_down_under:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:neocrome:land_down_under:*:*:*:*:*:*:*:*range: <=700.03
    • cpe:2.3:a:neocrome:land_down_under:601:*:*:*:*:*:*:*
    • cpe:2.3:a:neocrome:land_down_under:602:*:*:*:*:*:*:*
    • cpe:2.3:a:neocrome:land_down_under:700.01:*:*:*:*:*:*:*
    • cpe:2.3:a:neocrome:land_down_under:700.02:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.