CVE-2003-0736

phpwebsite < 0.9.0 - Cross-Site Scripting via Calendar Day Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2003-0736. PoCs published by Lorenzo Hernandez Garcia-Hierro.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP Website's Calendar, PageMaster, Search, and Fatcat modules. The attack involves crafting a malicious URL that injects script code into the user's browser context when followed.

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Lorenzo Hernandez Garcia-Hierro · textwebappsphp
https://www.exploit-db.com/exploits/23016

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP Website's Calendar, PageMaster, Search, and Fatcat modules. The attack involves crafting a malicious URL that injects script code into the user's browser context when followed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PHP Website (versions affected by CVE-2003-0736)
No auth needed
Prerequisites: Access to the target web application · User interaction to follow the malicious link
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lorenzo Hernandez Garcia-Hierro · textwebappsphp
https://www.exploit-db.com/exploits/23015

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP Website's Calendar, PageMaster, Search, and Fatcat modules. The PoC shows how an attacker can inject malicious script code via a crafted URL, which executes in the context of the vulnerable site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PHP Website (versions affected by CVE-2003-0736)
No auth needed
Prerequisites: A vulnerable instance of PHP Website with exposed modules
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lorenzo Hernandez Garcia-Hierro · textwebappsphp
https://www.exploit-db.com/exploits/23017

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP Website's Calendar, PageMaster, Search, and Fatcat modules. The PoC provides a malicious URL that injects arbitrary script code into the user's browser context when followed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PHP Website (versions affected by CVE-2003-0736)
No auth needed
Prerequisites: A vulnerable instance of PHP Website · User interaction to follow the malicious link
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lorenzo Hernandez Garcia-Hierro · textwebappsphp
https://www.exploit-db.com/exploits/23014

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP Website's Calendar module. The attack involves injecting malicious script code via the 'day' parameter, which is rendered in the user's browser context.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PHP Website (Calendar module)
No auth needed
Prerequisites: Access to a vulnerable PHP Website instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106252188522715&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/664422
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106062021711496&w=2

Scores

EPSS 0.0259
EPSS Percentile 83.2%

Details

Status published
Products (1)
phpwebsite/phpwebsite < 0.9.0
Published Oct 20, 2003
Tracked Since Feb 18, 2026