Vulnerabilities > CVE-2002-1931 - Cross-Site Scripting vulnerability in PHP Arena Pafiledb 1.1.3/2.1.1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
php-arena
nessus

Summary

Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

Vulnerable Configurations

Part Description Count
Application
Php_Arena
2

Nessus

NASL familyCGI abuses : XSS
NASL idPAFILEDB_XSS.NASL
descriptionThe version of paFileDB installed on the remote host is vulnerable to cross-site scripting attacks due to its failure to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id11479
published2003-03-26
reporterThis script is Copyright (C) 2003-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/11479
titlepaFileDB pafiledb.php id Parameter XSS