4.3
CVSSv2

CVE-2003-1347

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 450
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote malicious users to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.

Vulnerable Product Search on Vulmon Subscribe to Product

geeklog geeklog 1.3.7

Exploits

source: wwwsecurityfocuscom/bid/6602/info Geeklog is prone to a cross-site scripting vulnerability in the 'usersphp' script This issue is due to insufficient sanitization of input submitted in URI parameters As a result, an attacker may create a malicious link to a site hosting Geeklog, which contains malicious HTML or script code W ...
source: wwwsecurityfocuscom/bid/6601/info The Geeklog 'profilesphp' script is prone to multiple cross-site scripting vulnerabilities This issue is due to insufficient sanitization of input submitted in URI parameters As a result, an attacker may create a malicious link to a site hosting Geeklog, which contains malicious HTML or script ...
source: wwwsecurityfocuscom/bid/6604/info Geeklog is prone to HTML injection attacks The user account 'Homepage' field is not sufficiently sanitized of HTML and script code As a result, a malicious user may inject malicious HTML and script code into this field When the malicious user's account information is displayed to other web use ...
source: wwwsecurityfocuscom/bid/6603/info Geeklog is prone to a cross-site scripting vulnerability in the 'commentphp' script This issue is due to insufficient sanitization of input submitted in URI parameters As a result, an attacker may create a malicious link to a site hosting Geeklog, which contains malicious HTML or script code ...