CVE-2013-7289

Andy's PHP Knowledgebase <0.95.8 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) email, or (4) username parameter.

Scores

EPSS 0.0031
EPSS Percentile 53.9%

Details

CWE
CWE-79
Status published
Products (50)
aphpkb/aphpkb < 0.95.7
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
aphpkb/aphpkb
... and 40 more
Published Jan 10, 2014
Tracked Since Feb 18, 2026