Unrated severityNVD Advisory· Published May 29, 2004· Updated Apr 16, 2026
CVE-2004-2038
CVE-2004-2038
Description
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.
Affected products
5cpe:2.3:a:neocrome:land_down_under:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:neocrome:land_down_under:*:*:*:*:*:*:*:*range: <=700.03
- cpe:2.3:a:neocrome:land_down_under:601:*:*:*:*:*:*:*
- cpe:2.3:a:neocrome:land_down_under:602:*:*:*:*:*:*:*
- cpe:2.3:a:neocrome:land_down_under:700.01:*:*:*:*:*:*:*
- cpe:2.3:a:neocrome:land_down_under:700.02:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/11739nvdPatchVendor Advisory
- www.osvdb.org/6508nvdPatchVendor Advisory
- www.osvdb.org/6510nvdPatchVendor Advisory
- www.osvdb.org/6511nvdPatchVendor Advisory
- ldu.neocrome.net/page.phpnvd
- marc.infonvd
- securitytracker.com/alerts/2004/May/1010335.htmlnvd
- www.securityfocus.com/bid/10435nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16284nvd
News mentions
0No linked articles in our index yet.