Back

CVE-2003-0416

Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.

Published: Jun 30, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
bandmin bandmin 1.4

GitHub Security Advisory GHSA-9x2r-5f7q-7jgp

Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 4.27%

Top 10% most likely to be exploited

Threat Score 28.5 / 100

Data Sources

NVD EPSS GitHub