7.5
CVSSv2

CVE-2002-1070

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote malicious users to execute script as other PHPWiki users via the pagename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php-wiki php-wiki 1.2

php-wiki php-wiki 1.2.1

php-wiki php-wiki 1.2.2

php-wiki php-wiki 1.3.2

php-wiki php-wiki 1.3.1

php-wiki php-wiki 1.3.3

Exploits

source: wwwsecurityfocuscom/bid/5254/info PHP-Wiki does not sufficiently sanitize HTML from URI parameters, making it prone to cross-site scripting attacks An attacker may exploit this condition by enticing users to visit a malicious link which contains attacker-supplied script code PHP-Wiki may be used as a module for other software s ...