4.3
CVSSv2

CVE-2003-1536

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dcp-portal dcp-portal 5.3.1

Exploits

source: wwwsecurityfocuscom/bid/7144/info It has been reported that DCP-Portal does not sufficiently filter URI parameters supplied to the DCP-Portal 'calender' script As a result of this deficiency, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitima ...