4.3
CVSSv2

CVE-2004-1537

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary web script via the img parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpkit phpkit 1.6.02

phpkit phpkit 1.6.03

phpkit phpkit 1.6.1

Exploits

source: wwwsecurityfocuscom/bid/11725/info It is reported that PHPKIT is susceptible to cross-site scripting and SQL injection vulnerabilities The cross-site scripting issue is present in a parameter of the 'popupphp' script An attacker can exploit this issue by creating a malicious link containing HTML and script code and send this l ...