Advertisement






Php Web Statistik Multiple Vulnerabilities

CVE Category Price Severity
CVE-2018-11770 CWE-79 Unknown High
Author Risk Exploitation Type Date
Mehmet eMIrcan High Remote 2005-12-12
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2005110071

Below is a copy:

PHP Web Statistik Multiple Vulnerabilities

Name              Multiple Vulnerabilities in PHP Web Statistik
  Systems Affected  PHP Web Statistik (verified on 1.4)
  Severity          Medium Risk
  Vendor            www.php-web-statistik.de
  Advisory          http://www.ush.it/2005/11/19/php-web-statistik/
  Author            Francesco ?aScii? Ongaro (ascii at katamail . com)
  Date              20051119

PHP Web Statistik is vulnerable to javascript and HTML injection using
the unchecked $lastnumber variable, proper input validation will fix.
Just place an intval() at the right row. Other vulnerabilities has been
discovered later.

Advisory released on 20051119:
Php Web Statistik Multiple Vulnerabilities
http://www.ush.it/2005/11/19/php-web-statistik/

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum