CVE-2004-0067

Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.
References
Link Resource
http://marc.info/?l=bugtraq&m=107394912715478&w=2
http://secunia.com/advisories/26628 Vendor Advisory
http://securitytracker.com/id?1018613
http://www.osvdb.org/3473
http://www.osvdb.org/3474
http://www.osvdb.org/3475
http://www.osvdb.org/3476
http://www.osvdb.org/3477
http://www.osvdb.org/3478
http://www.osvdb.org/3479
http://www.securityfocus.com/archive/1/477881/100/0/threaded
http://www.securityfocus.com/bid/11868
http://www.securityfocus.com/bid/11880
http://www.securityfocus.com/bid/11882
http://www.securityfocus.com/bid/11888
http://www.securityfocus.com/bid/11890
http://www.securityfocus.com/bid/11891
http://www.securityfocus.com/bid/11894
http://www.securityfocus.com/bid/11903
http://www.securityfocus.com/bid/11904
http://www.securityfocus.com/bid/11905
http://www.securityfocus.com/bid/11906
http://www.securityfocus.com/bid/11907
http://www.vupen.com/english/advisories/2007/2995 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/14212
https://exchange.xforce.ibmcloud.com/vulnerabilities/36285
http://marc.info/?l=bugtraq&m=107394912715478&w=2
http://secunia.com/advisories/26628 Vendor Advisory
http://securitytracker.com/id?1018613
http://www.osvdb.org/3473
http://www.osvdb.org/3474
http://www.osvdb.org/3475
http://www.osvdb.org/3476
http://www.osvdb.org/3477
http://www.osvdb.org/3478
http://www.osvdb.org/3479
http://www.securityfocus.com/archive/1/477881/100/0/threaded
http://www.securityfocus.com/bid/11868
http://www.securityfocus.com/bid/11880
http://www.securityfocus.com/bid/11882
http://www.securityfocus.com/bid/11888
http://www.securityfocus.com/bid/11890
http://www.securityfocus.com/bid/11891
http://www.securityfocus.com/bid/11894
http://www.securityfocus.com/bid/11903
http://www.securityfocus.com/bid/11904
http://www.securityfocus.com/bid/11905
http://www.securityfocus.com/bid/11906
http://www.securityfocus.com/bid/11907
http://www.vupen.com/english/advisories/2007/2995 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/14212
https://exchange.xforce.ibmcloud.com/vulnerabilities/36285
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgedview:phpgedview:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=107394912715478&w=2 - () http://marc.info/?l=bugtraq&m=107394912715478&w=2 -
References () http://secunia.com/advisories/26628 - Vendor Advisory () http://secunia.com/advisories/26628 - Vendor Advisory
References () http://securitytracker.com/id?1018613 - () http://securitytracker.com/id?1018613 -
References () http://www.osvdb.org/3473 - () http://www.osvdb.org/3473 -
References () http://www.osvdb.org/3474 - () http://www.osvdb.org/3474 -
References () http://www.osvdb.org/3475 - () http://www.osvdb.org/3475 -
References () http://www.osvdb.org/3476 - () http://www.osvdb.org/3476 -
References () http://www.osvdb.org/3477 - () http://www.osvdb.org/3477 -
References () http://www.osvdb.org/3478 - () http://www.osvdb.org/3478 -
References () http://www.osvdb.org/3479 - () http://www.osvdb.org/3479 -
References () http://www.securityfocus.com/archive/1/477881/100/0/threaded - () http://www.securityfocus.com/archive/1/477881/100/0/threaded -
References () http://www.securityfocus.com/bid/11868 - () http://www.securityfocus.com/bid/11868 -
References () http://www.securityfocus.com/bid/11880 - () http://www.securityfocus.com/bid/11880 -
References () http://www.securityfocus.com/bid/11882 - () http://www.securityfocus.com/bid/11882 -
References () http://www.securityfocus.com/bid/11888 - () http://www.securityfocus.com/bid/11888 -
References () http://www.securityfocus.com/bid/11890 - () http://www.securityfocus.com/bid/11890 -
References () http://www.securityfocus.com/bid/11891 - () http://www.securityfocus.com/bid/11891 -
References () http://www.securityfocus.com/bid/11894 - () http://www.securityfocus.com/bid/11894 -
References () http://www.securityfocus.com/bid/11903 - () http://www.securityfocus.com/bid/11903 -
References () http://www.securityfocus.com/bid/11904 - () http://www.securityfocus.com/bid/11904 -
References () http://www.securityfocus.com/bid/11905 - () http://www.securityfocus.com/bid/11905 -
References () http://www.securityfocus.com/bid/11906 - () http://www.securityfocus.com/bid/11906 -
References () http://www.securityfocus.com/bid/11907 - () http://www.securityfocus.com/bid/11907 -
References () http://www.vupen.com/english/advisories/2007/2995 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2995 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/14212 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/14212 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/36285 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/36285 -

Information

Published : 2004-02-17 05:00

Updated : 2024-11-20 23:47


NVD link : CVE-2004-0067

Mitre link : CVE-2004-0067

CVE.ORG link : CVE-2004-0067


JSON object : View

Products Affected

phpgedview

  • phpgedview
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')