peter bassill · operator
$ cve CVE-2003-1372 JSON

CVE-2003-1372 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 73)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.5% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (4)

VendorProduct
linuxlinux kernel
microsoftall windows
myphpnukemyphpnuke
unixunix

Public exploits

SourceTitleDate
exploit-dbmyPHPNuke 1.8.8 - 'links.php' Cross-Site Scripting2003-02-20

References

→ the Explorer  ·  watch your stack  ·  NVD