Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- exchange.xforce.ibmcloud.com: phpkit-include-xss(13590) vdb-entryx_transferred
- securityfocus.com: 8960 vdb-entryx_transferred
- lists.grok.org.uk: 20031102 [bWM#017] Cross-Site-Scripting @ PHPKIT mailing-listx_transferred
- http://badwebmasters.net/advisory/017/ x_transferred