Back to search
CVE-2004-1655
Published: Feb 20, 2005
Modified: Aug 8, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20040901 Multiple Vulnerabilities In phpWebsite
mailing-list
x_refsource_BUGTRAQ
http://www.gulftech.org/?node=research&article_id=00048-08312004
x_refsource_MISC
11088
vdb-entry
x_refsource_BID
1011120
vdb-entry
x_refsource_SECTRACK
phpwebsite-notes-script-injection(17203)
vdb-entry
x_refsource_XF
phpwebsite-comments-module-xss(17202)
vdb-entry
x_refsource_XF
12438
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now