CVE-2013-7277

Andy's PHP Knowledgebase <0.95.8 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to saa.php, (2) username parameter to login.php, or (3) keyword_list parameter to keysearch.php.

Scores

EPSS 0.0035
EPSS Percentile 57.5%

Details

CWE
CWE-79
Status published
Products (50)
aphpkb/aphpkb < 0.95.7
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
... and 40 more
Published Jan 08, 2014
Tracked Since Feb 18, 2026