VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2063

CVE-2004-2063

Description

Cross-site scripting in AntiBoard 0.7.2 and earlier via the feedback parameter in antiboard.php allows remote attackers to inject arbitrary HTML or script.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting in AntiBoard 0.7.2 and earlier via the feedback parameter in antiboard.php allows remote attackers to inject arbitrary HTML or script.

Vulnerability

AntiBoard versions 0.7.2 and earlier are vulnerable to a reflected cross-site scripting (XSS) issue in antiboard.php. The feedback parameter is not properly sanitized before being returned to the user, allowing injection of arbitrary HTML or JavaScript. This affects the PHP-based bulletin board system [1][2].

Exploitation

An attacker can craft a malicious URL containing a feedback parameter with embedded script code. No authentication or special privileges are required; the victim only needs to visit the crafted link. The attack is performed via a simple HTTP GET request to antiboard.php [2].

Impact

Successful exploitation allows the attacker to execute arbitrary HTML and JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive information. The attacker gains no server-side access but can perform actions on behalf of the victim within the application [1][2].

Mitigation

No official patch was released for this vulnerability. The software is likely end-of-life and no longer maintained. Users should consider migrating to an alternative bulletin board system or applying input validation filters as a workaround [1][2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

8
  • cpe:2.3:a:antiboard:antiboard:0.6:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:antiboard:antiboard:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.61:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.62:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.63:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:antiboard:antiboard:0.7.2:*:*:*:*:*:*:*
    • (no CPE)range: <=0.7.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.