4.3

CVE-2005-3552

Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpkitPhpkit Updaterc2 Version <= 1.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.777
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00110.html
http://secunia.com/advisories/17479
http://securitytracker.com/id?1015167
http://www.hardened-php.net/advisory_212005.80.html
Vendor Advisory
http://www.osvdb.org/20553
http://www.osvdb.org/20554
http://www.osvdb.org/20555
http://www.osvdb.org/20556
http://www.osvdb.org/20557
http://www.osvdb.org/20558
http://www.osvdb.org/20559
http://www.securityfocus.com/bid/15354
http://www.vupen.com/english/advisories/2005/2344
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/23003
https://exchange.xforce.ibmcloud.com/vulnerabilities/23004
https://exchange.xforce.ibmcloud.com/vulnerabilities/23006
https://exchange.xforce.ibmcloud.com/vulnerabilities/23007
https://exchange.xforce.ibmcloud.com/vulnerabilities/23008
https://exchange.xforce.ibmcloud.com/vulnerabilities/23009