Overview
PhpWebSite contains multiple cross-site scripting vulnerabilities that may allow an attacker to execute arbitrary code on users' web browser.
Description
PhpWebSite is an open-source web content management system. Certain PhpWebSite modules fail to properly filter URLs for malicious content. This may allow scripting code to be inserted into a URL and then executed within the users' web browser. The following PhpWebSite modules contain this vulnerability:
In addition, error pages generated by PhpWebSite are reported to be vulnerable. |
Impact
An attacker may be able to execute arbitrary code in a guest or logged-in users' web browser with the privileges of that user. |
Solution
Apply a Patch
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.gulftech.org/?node=research&article_id=00048-08312004
- http://www.securitytracker.com/alerts/2004/Aug/1011120.html
- http://www.securityfocus.com/archive/1/332561
- http://marc.theaimsgroup.com/?l=bugtraq&m=106062021711496&w=2
- http://www.osvdb.org/displayvuln.php?osvdb_id=9445
- http://www.osvdb.org/displayvuln.php?osvdb_id=3842
- http://www.osvdb.org/displayvuln.php?osvdb_id=3846
- http://www.osvdb.org/displayvuln.php?osvdb_id=3845
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0736
- http://www.phpwebsite.appstate.edu/index.php?module=announce&ANN_user_op=view&ANN_id=822
Acknowledgements
This vulnerability was publicly reported by GulfTech Security.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2003-0736 |
Severity Metric: | 0.60 |
Date Public: | 2004-08-31 |
Date First Published: | 2004-10-19 |
Date Last Updated: | 2004-10-19 19:09 UTC |
Document Revision: | 128 |