CVE-2003-1554
Scoznet Scozbook - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.
References (6)
Scores
EPSS
0.0047
EPSS Percentile
64.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
scoznet/scozbook
Timeline
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026