4.3
CVSSv2

CVE-2003-1372

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote malicious users to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

myphpnuke myphpnuke 1.8.8

Exploits

source: wwwsecurityfocuscom/bid/6892/info Reportedly, myPHPNuke 'linksphp' does not adequately filter HTML code thus making it prone to cross-site scripting attacks It is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user All code will be executed w ...