Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) email, or (4) username parameter.
                
            References
                    | Link | Resource | 
|---|---|
| http://osvdb.org/101466 | |
| http://secunia.com/advisories/56228 | Vendor Advisory | 
| http://aphpkb.blogspot.dk/2013/12/release-of-aphpkb-0958.html | Patch Vendor Advisory | 
| http://sourceforge.net/p/aphpkb/code/91 | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2014-01-10 08:47
Updated : 2014-02-24 18:01
NVD link : CVE-2013-7289
Mitre link : CVE-2013-7289
JSON object : View
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
                aphpkb
- aphpkb
 


