4.3
CVSSv2

CVE-2003-1453

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 up to and including 1.3.9 and XOOPS 2.0 up to and including 2.0.1 allows remote malicious users to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops 2.0.1

xoops xoops 1.3.9

xoops xoops 2.0

xoops xoops 1.3.5

xoops xoops 1.3.6

xoops xoops 1.3.7

xoops xoops 1.3.8

Exploits

source: wwwsecurityfocuscom/bid/7434/info A HTML injection vulnerability has been discovered in Xoops The problem occurs due to insufficient filtering of HTML and script code by the MyTextSanitizer script Successful exploitation of this vulnerability may allow a malicious Xoops user to execute arbitrary HTML or script code within the b ...