CVE-2002-2178

phpWebSite 0.8.3 - Cross-Site Scripting via article.php sid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2002-2178. PoCs published by Sp.IC, [email protected].

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpWebSite due to insufficient sanitization of HTML tags in the 'article.php' script. An attacker can craft a malicious link containing arbitrary HTML and script code, which executes in the context of the vulnerable site when visited by a user.

Description

Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Sp.IC · textwebappsphp
https://www.exploit-db.com/exploits/21899

This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpWebSite due to insufficient sanitization of HTML tags in the 'article.php' script. An attacker can craft a malicious link containing arbitrary HTML and script code, which executes in the context of the vulnerable site when visited by a user.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phpWebSite (version not specified)
No auth needed
Prerequisites: A vulnerable instance of phpWebSite · A web browser to visit the malicious link
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/21864

This exploit demonstrates a stored XSS vulnerability in phpWebSite where malicious HTML code in news posts is not properly filtered, allowing arbitrary script execution in the context of the victim's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phpWebSite (version not specified)
No auth needed
Prerequisites: Ability to post news content on a vulnerable phpWebSite instance
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5864
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/293879
Exploit, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10256.php

Scores

EPSS 0.0175
EPSS Percentile 75.6%

Details

Status published
Products (1)
phpwebsite/phpwebsite 0.8.3
Published Dec 31, 2002
Tracked Since Feb 18, 2026