4.3
CVSSv2

CVE-2002-1929

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 up to and including 3.0 allows remote malicious users to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions.

Vulnerable Product Search on Vulmon Subscribe to Product

php arena pafiledb 3.0

php arena pafiledb 1.1.3

php arena pafiledb 2.1.1

Exploits

source: wwwsecurityfocuscom/bid/6018/info PHP Arena paFileDB is prone to cross-site scripting attacks An attacker may construct a malicious link to the vulnerable script which contains arbitrary HTML and script code If this link is visited by a web user, the attacker-supplied code will execute in their web client in the security contex ...