Vulnerabilities > CVE-2003-0481 - Unspecified vulnerability in Gero Kohnert Tutos 1.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Tutos 1.1 File_Select.PHP Cross-Site Scripting Vulnerability. CVE-2003-0481. Webapps exploit for php platform |
id | EDB-ID:22818 |
last seen | 2016-02-02 |
modified | 2003-06-20 |
published | 2003-06-20 |
reporter | François SORIN |
source | https://www.exploit-db.com/download/22818/ |
title | Tutos 1.1 File_Select.PHP Cross-Site Scripting Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | TUTOS_SQL_XSS.NASL |
description | The remote host is running Tutos, an open source team organization software package written in PHP. The remote version of this software is vulnerable to multiple input validation flaws that could allow an authenticated user to perform a cross-site scripting attack or a SQL injection against the remote service. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14784 |
published | 2004-09-21 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14784 |
title | TUTOS < 1.2 Multiple Input Validation Vulnerabilities |
code |
|