CVE-2003-0736 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module (2) the fatcat_id parameter in the fatcat module (3) the PAGE_id parameter in the pagemaster module (4) the PDA_limit parameter in the search and (5) possibly other parameters in the calendar fatcat and pagemaster modules.

Reference

http://marc.info/?l=bugtraq&m=106062021711496&w=2 http://marc.info/?l=bugtraq&m=106252188522715&w=2 http://www.kb.cert.org/vuls/id/664422

Share on: