CVE-2005-3552
Phpkit < 1.6.1 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
References (19)
Scores
EPSS
0.0142
EPSS Percentile
80.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
phpkit/phpkit
< 1.6.1
Timeline
Published
Nov 16, 2005
Tracked Since
Feb 18, 2026