4.3
CVSSv2

CVE-2003-1498

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the zoom_query parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wrensoft zoom search engine

Exploits

source: wwwsecurityfocuscom/bid/8823/info WrenSoft Zoom Search Engine is prone to a cross-site scripting issue in the software's search module A remote attacker may be able to execute HTML or script code in a user's browser The problem occurs because the software fails to properly sanitize user-supplied input An attacker may be able t ...