Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2656
CVE-2004-2656
Description
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.
Affected products
2cpe:2.3:a:open_source_development_network:slashcode:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:open_source_development_network:slashcode:*:*:*:*:*:*:*:*range: <=r_2_5_0_41
- cpe:2.3:a:open_source_development_network:slashcode:2.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/13491nvdPatchVendor Advisory
- www.securityfocus.com/bid/11993nvdPatch
- www.slashcode.com/slash/04/12/20/1946225.shtmlnvdPatchVendor Advisory
- www.osvdb.org/21874nvdExploitPatch
- www.osvdb.org/21875nvdExploitPatch
- archives.neohapsis.com/archives/bugtraq/2004-12/0170.htmlnvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/18508nvd
News mentions
0No linked articles in our index yet.