Vulnerabilities > CVE-2007-3001 - Cross-Site Scripting vulnerability in PHP Jackknife PHP Jackknife 2.21

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
php-jackknife
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary web script or HTML via (1) the sUName parameter to UserArea/Authenticate.php, (2) the sAccountUnq parameter to UserArea/NewAccounts/index.php, or the (3) iCategoryUnq, (4) iDBLoc, (5) iTtlNumItems, (6) iNumPerPage, or (7) sSort parameter to G_Display.php, different vectors than CVE-2005-4239.

Vulnerable Configurations

Part Description Count
Application
Php_Jackknife
1

Exploit-Db

  • descriptionPHP JackKnife 2.21 (PHPJK) UserArea/NewAccounts/index.php sAccountUnq Parameter XSS. CVE-2007-3001. Webapps exploit for php platform
    idEDB-ID:30115
    last seen2016-02-03
    modified2007-05-31
    published2007-05-31
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/30115/
    titlePHP JackKnife 2.21 PHPJK UserArea/NewAccounts/index.php sAccountUnq Parameter XSS
  • descriptionPHP JackKnife 2.21 (PHPJK) G_Display.php Multiple Parameter XSS. CVE-2007-3001. Webapps exploit for php platform
    idEDB-ID:30116
    last seen2016-02-03
    modified2007-05-31
    published2007-05-31
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/30116/
    titlePHP JackKnife 2.21 PHPJK G_Display.php Multiple Parameter XSS
  • descriptionPHP JackKnife 2.21 (PHPJK) UserArea/Authenticate.php sUName Parameter XSS. CVE-2007-3001. Webapps exploit for php platform
    idEDB-ID:30114
    last seen2016-02-03
    modified2007-05-31
    published2007-05-31
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/30114/
    titlePHP JackKnife 2.21 PHPJK UserArea/Authenticate.php sUName Parameter XSS