Vulnerabilities > CVE-2003-0736 - Unspecified vulnerability in PHPwebsite
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 calendar Module day Parameter XSS. CVE-2003-0736. Webapps exploit for php platform id EDB-ID:23014 last seen 2016-02-02 modified 2003-08-11 published 2003-08-11 reporter Lorenzo Hernandez Garcia-Hierro source https://www.exploit-db.com/download/23014/ title phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 calendar Module day Parameter XSS description phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module PAGE_id Parameter XSS. CVE-2003-0736. Webapps exploit for php platform id EDB-ID:23016 last seen 2016-02-02 modified 2003-08-11 published 2003-08-11 reporter Lorenzo Hernandez Garcia-Hierro source https://www.exploit-db.com/download/23016/ title phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module PAGE_id Parameter XSS description phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module PDA_limit Parameter XSS. CVE-2003-0736. Webapps exploit for php platform id EDB-ID:23017 last seen 2016-02-02 modified 2003-08-11 published 2003-08-11 reporter Lorenzo Hernandez Garcia-Hierro source https://www.exploit-db.com/download/23017/ title phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module PDA_limit Parameter XSS description phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module fatcat_id Parameter XSS. CVE-2003-0736 . Webapps exploit for php platform id EDB-ID:23015 last seen 2016-02-02 modified 2003-08-11 published 2003-08-11 reporter Lorenzo Hernandez Garcia-Hierro source https://www.exploit-db.com/download/23015/ title phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module fatcat_id Parameter XSS
Nessus
NASL family | CGI abuses |
NASL id | PHPWEBSITE_MULTIPLE_FLAWS.NASL |
description | There are multiple flaws in the remote version of phpWebSite that may allow an attacker to gain the control of the remote database, or to disable this site entirely. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11816 |
published | 2003-08-11 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11816 |
title | phpWebSite < 0.9.x Multiple Vulnerabilities |