CVE-2003-1453
Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.
- Affected products
- Xoops
- Xoops
- = 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 2.0, 2.0.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.5% (71th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2007-10-23
CVE-2003-1453 at NVD
1 known exploit for CVE-2003-1453
Proof-of-concept code and exploit modules indexed by Sploitus