Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026
CVE-2004-2550
CVE-2004-2550
Description
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:xperience:sandsurfer:1.6.2:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:xperience:sandsurfer:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:xperience:sandsurfer:1.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:xperience:sandsurfer:1.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:xperience:sandsurfer:1.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:xperience:sandsurfer:1.7.0:*:*:*:*:*:*:*
- (no CPE)range: <1.7.1
Patches
Vulnerability mechanics
References
5- secunia.com/advisories/11028nvdPatchVendor Advisory
- www.osvdb.org/4132nvdPatch
- www.securityfocus.com/bid/9801nvdPatch
- sourceforge.net/forum/forum.phpnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15377nvd
News mentions
0No linked articles in our index yet.