4.3
CVSSv2

CVE-2009-2884

Published: 20/08/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote malicious users to inject arbitrary web script or HTML via the rank parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpscriptsnow world\\'s tallest buildings -

Exploits

source: wwwsecurityfocuscom/bid/44306/info Multiple PHP Scripts Now products are prone to an input-validation vulnerability that can be exploited to conduct SQL-injection and cross-site scripting attacks Exploiting this vulnerability could allow an attacker to steal cookie-based authentication credentials, compromise the application, ac ...