Vulnerabilities > CVE-2003-0416 - Unspecified vulnerability in Bandmin 1.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Bandmin 1.4 Cross-Site Scripting Vulnerability. CVE-2003-0416. Webapps exploit for cgi platform |
id | EDB-ID:22669 |
last seen | 2016-02-02 |
modified | 2003-05-28 |
published | 2003-05-28 |
reporter | silent needel |
source | https://www.exploit-db.com/download/22669/ |
title | Bandmin 1.4 - Cross-Site Scripting Vulnerability |
Nessus
NASL family | CGI abuses : XSS |
NASL id | BANDMIN_XSS.NASL |
description | The remote host is running the Bandmin CGI suite. There is a cross-site scripting issue in this suite that may allow an attacker to steal your users cookies. The flaw lies in the cgi bandwitdh/index.cgi |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11672 |
published | 2003-05-29 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11672 |
title | Bandmin 1.4 index.cgi Multiple Parameter XSS |
code |
|