4.3
CVSSv2

CVE-2002-1954

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote malicious users to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.2.3

Vendor Advisories

Debian Bug report logs - #336645 PHP 441 fixes security bugs Package: php4; Maintainer for php4 is (unknown); Reported by: Florian Weimer <fw@denebenyode> Date: Mon, 31 Oct 2005 19:48:02 UTC Severity: grave Tags: security Found in version php4/4:4310-16 Fixed in version php4/4:442-1 Done: Adam Conrad <adconrad ...

Exploits

source: wwwsecurityfocuscom/bid/7805/info Scripts that include the PHP phpinfo() debugging function may be prone to cross-site scripting attacks This could permit remote attackers to create a malicious link to a vulnerable PHP script that includes hostile client-side script code or HTML If this link is visited, the attacker-supplied cod ...