CVE
- Id
- 5458
- CVE No.
- CVE-2002-1070
- Status
- Candidate
- Description
- Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall
- Comments
- Christey> CONFIRM:http://cvs.sourceforge.net/viewcvs.py/phpwiki/phpwiki/lib/Request.php | This URL is a changelog for Request.php. For revsion 1.17, | dated 20020909, the author says "Prevent from possible XSS attacks" | and includes a sample exploit for the pagename parameter.