CVE-2003-0318: XSS
Published May 22, 2003
·Updated
Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke<=6.0
Event History
May 22, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 9, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0318?
CVE-2003-0318 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2003-0318?
To fix CVE-2003-0318, upgrade to a version of PHP-Nuke later than 6.0 that addresses this vulnerability.
3
What type of vulnerability is CVE-2003-0318?
CVE-2003-0318 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
4
Which versions of PHP-Nuke are affected by CVE-2003-0318?
CVE-2003-0318 affects PHP-Nuke versions 6.0 and earlier.
5
Can CVE-2003-0318 be exploited remotely?
Yes, CVE-2003-0318 can be exploited remotely by attackers who manipulate the 'year' parameter.