4.3
CVE-2003-1506
- EPSS 1.73%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:04:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Daniel Barron ≫ Dansguardian Version3.0
Daniel Barron ≫ Dansguardian Version3.1_r5
Daniel Barron ≫ Dansguardian Version3.1_r6
Daniel Barron ≫ Dansguardian Version3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.73% | 0.747 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://securityreason.com/securityalert/3299
http://www.securityfocus.com/archive/1/342160
http://www.securityfocus.com/archive/1/342551
http://www.securityfocus.com/archive/1/342577
http://www.securityfocus.com/bid/8876
https://exchange.xforce.ibmcloud.com/vulnerabilities/13507