4.3
CVSSv2

CVE-2004-0067

Published: 17/02/2004 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 500
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpGedView prior to 2.65 allow remote malicious users to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgedview phpgedview

Exploits

source: wwwsecurityfocuscom/bid/11890/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11905/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11868/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11906/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11910/info It is reported that PhpGedView is susceptible to a remote SQL injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input prior to including it in an SQL query This issue allows remote attackers to manipulate query logic, leading to unauth ...
source: wwwsecurityfocuscom/bid/11925/info It is reported that PhpGedView is susceptible to a remote SQL injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input prior to including it in an SQL query This issue allows remote attackers to manipulate query logic The issue could t ...
source: wwwsecurityfocuscom/bid/11882/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11888/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11904/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11903/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11891/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11894/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11907/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...
source: wwwsecurityfocuscom/bid/11880/info It is reported that PhpGedView is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code ...