CVE-2003-0416 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 4.3% (pctl 91)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 4.27% — more likely to be exploited than 91% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-06-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| bandmin | bandmin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Bandmin 1.4 - Cross-Site Scripting | 2003-05-28 |
References
→ the Explorer · watch your stack · NVD