CVE-2013-7289
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) email, or (4) username parameter.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| aphpkb | aphpkb | {"endIncluding":"0.95.7"} | |
| aphpkb | aphpkb | 0.1 | |
| aphpkb | aphpkb | 0.2 | |
| aphpkb | aphpkb | 0.3 | |
| aphpkb | aphpkb | 0.4 | |
| aphpkb | aphpkb | 0.5 | |
| aphpkb | aphpkb | 0.6 | |
| aphpkb | aphpkb | 0.9 | |
| aphpkb | aphpkb | 0.21 | |
| aphpkb | aphpkb | 0.31 | |
| aphpkb | aphpkb | 0.33 | |
| aphpkb | aphpkb | 0.35 | |
| aphpkb | aphpkb | 0.38 | |
| aphpkb | aphpkb | 0.39 | |
| aphpkb | aphpkb | 0.41 | |
| aphpkb | aphpkb | 0.42 | |
| aphpkb | aphpkb | 0.43 | |
| aphpkb | aphpkb | 0.44 | |
| aphpkb | aphpkb | 0.45 | |
| aphpkb | aphpkb | 0.51 | |
| aphpkb | aphpkb | 0.52 | |
| aphpkb | aphpkb | 0.53 | |
| aphpkb | aphpkb | 0.54 | |
| aphpkb | aphpkb | 0.55 | |
| aphpkb | aphpkb | 0.56 | |
| aphpkb | aphpkb | 0.57 | |
| aphpkb | aphpkb | 0.58 | |
| aphpkb | aphpkb | 0.59 | |
| aphpkb | aphpkb | 0.61 | |
| aphpkb | aphpkb | 0.62 | |
| aphpkb | aphpkb | 0.63 | |
| aphpkb | aphpkb | 0.64 | |
| aphpkb | aphpkb | 0.65 | |
| aphpkb | aphpkb | 0.66 | |
| aphpkb | aphpkb | 0.67 | |
| aphpkb | aphpkb | 0.70 | |
| aphpkb | aphpkb | 0.71 | |
| aphpkb | aphpkb | 0.72 | |
| aphpkb | aphpkb | 0.73 | |
| aphpkb | aphpkb | 0.74 | |
| aphpkb | aphpkb | 0.75 | |
| aphpkb | aphpkb | 0.76 | |
| aphpkb | aphpkb | 0.77 | |
| aphpkb | aphpkb | 0.78 | |
| aphpkb | aphpkb | 0.79 | |
| aphpkb | aphpkb | 0.80 | |
| aphpkb | aphpkb | 0.81 | |
| aphpkb | aphpkb | 0.82 | |
| aphpkb | aphpkb | 0.83 | |
| aphpkb | aphpkb | 0.84 | |
| aphpkb | aphpkb | 0.85 | |
| aphpkb | aphpkb | 0.86 | |
| aphpkb | aphpkb | 0.87 | |
| aphpkb | aphpkb | 0.88 | |
| aphpkb | aphpkb | 0.88.5 | |
| aphpkb | aphpkb | 0.88.6 | |
| aphpkb | aphpkb | 0.88.7 | |
| aphpkb | aphpkb | 0.88.8 | |
| aphpkb | aphpkb | 0.89 | |
| aphpkb | aphpkb | 0.91 | |
| aphpkb | aphpkb | 0.92 | |
| aphpkb | aphpkb | 0.92.1 | |
| aphpkb | aphpkb | 0.92.2 | |
| aphpkb | aphpkb | 0.92.3 | |
| aphpkb | aphpkb | 0.92.4 | |
| aphpkb | aphpkb | 0.92.5 | |
| aphpkb | aphpkb | 0.92.6 | |
| aphpkb | aphpkb | 0.92.7 | |
| aphpkb | aphpkb | 0.92.8 | |
| aphpkb | aphpkb | 0.92.9 | |
| aphpkb | aphpkb | 0.93.1 | |
| aphpkb | aphpkb | 0.93.2 | |
| aphpkb | aphpkb | 0.93.3 | |
| aphpkb | aphpkb | 0.93.4 | |
| aphpkb | aphpkb | 0.93.5 | |
| aphpkb | aphpkb | 0.93.6 | |
| aphpkb | aphpkb | 0.93.7 | |
| aphpkb | aphpkb | 0.93.8 | |
| aphpkb | aphpkb | 0.93.9 | |
| aphpkb | aphpkb | 0.94.1 | |
| aphpkb | aphpkb | 0.94.2 | |
| aphpkb | aphpkb | 0.94.3 | |
| aphpkb | aphpkb | 0.94.4 | |
| aphpkb | aphpkb | 0.94.5 | |
| aphpkb | aphpkb | 0.94.6 | |
| aphpkb | aphpkb | 0.94.7 | |
| aphpkb | aphpkb | 0.94.8 | |
| aphpkb | aphpkb | 0.94.9 | |
| aphpkb | aphpkb | 0.95 | |
| aphpkb | aphpkb | 0.95.1 | |
| aphpkb | aphpkb | 0.95.2 | |
| aphpkb | aphpkb | 0.95.3 | |
| aphpkb | aphpkb | 0.95.4 | |
| aphpkb | aphpkb | 0.95.5 | |
| aphpkb | aphpkb | 0.95.6 | |
| aphpkb | aphpkb | 0.361 | |
| aphpkb | aphpkb | 0.371 | |
References
- http://aphpkb.blogspot.dk/2013/12/release-of-aphpkb-0958.html
- http://osvdb.org/101466
- http://secunia.com/advisories/56228
- http://sourceforge.net/p/aphpkb/code/91
- http://aphpkb.blogspot.dk/2013/12/release-of-aphpkb-0958.html
- http://osvdb.org/101466
- http://secunia.com/advisories/56228
- http://sourceforge.net/p/aphpkb/code/91
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.