Back

CVE-2004-1202

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
phpcms phpcms 1.1.9
phpcms phpcms 1.2
phpcms phpcms 1.2.1

GitHub Security Advisory GHSA-m4wf-cgh7-9gv4

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 2.30%

Top 18% most likely to be exploited

Threat Score 27.9 / 100

Data Sources

NVD EPSS GitHub