4.3
CVSSv2

CVE-2002-2178

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote malicious users to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

phpwebsite phpwebsite 0.8.3

Exploits

source: wwwsecurityfocuscom/bid/5864/info phpWebSite is prone to cross-site scripting attacks This vulnerability is due to insufficient sanitization of HTML tags from URI parameters processed by the 'articlephp' script As a result, an attacker may construct a malicious link to this script which contains arbitrary HTML and script code ...
source: wwwsecurityfocuscom/bid/5802/info Problems with phpWebSite could make it possible to execute arbitrary script code in a vulnerable client phpWebSite does not sufficiently filter potentially malicious HTML code from news posts As a result, when a user views a news posting that contains malicious HTML code, the code contained in ...