CVE-2004-1655
phpwebsite 0.9.3-4 - Cross-Site Scripting via Comments Module CM_pid Parameter or Notes Module Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1655. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in phpWebSite, including XSS, SQL injection, and HTML injection, but does not contain actual exploit code. It outlines the vulnerabilities and their potential impact without providing a functional proof-of-concept.
Description
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.
Exploits (1)
The provided text describes multiple vulnerabilities in phpWebSite, including XSS, SQL injection, and HTML injection, but does not contain actual exploit code. It outlines the vulnerabilities and their potential impact without providing a functional proof-of-concept.