Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T02:05:12.485Z

Reserved: 2003-09-03T00:00:00

Link: CVE-2003-0736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2003-10-20T04:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2003-0736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.