CVE-2013-7289
Summary
| CVE | CVE-2013-7289 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-10 16:47:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, (3) email, or (4) username parameter. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS: 0.003090000 probability, percentile 0.540700000 (date 2026-05-01)
Problem Types: CWE-79 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aphpkb | Aphpkb | 0.1 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.2 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.21 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.3 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.31 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.33 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.35 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.361 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.371 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.38 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.39 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.4 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.41 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.42 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.43 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.44 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.45 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.51 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.52 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.53 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.54 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.55 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.56 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.57 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.58 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.59 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.6 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.61 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.62 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.63 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.64 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.65 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.66 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.67 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.70 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.71 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.72 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.73 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.74 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.75 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.76 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.77 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.78 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.79 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.80 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.81 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.82 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.83 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.84 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.85 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.86 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.87 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.88 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.88.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.88.6 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.88.7 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.88.8 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.89 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.9 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.91 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.1 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.2 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.3 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.4 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.6 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.7 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.8 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.92.9 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.1 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.2 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.3 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.4 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.6 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.7 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.8 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.93.9 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.1 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.2 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.3 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.4 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.6 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.7 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.8 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.94.9 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.1 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.2 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.3 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.4 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.5 | All | All | All |
| Application | Aphpkb | Aphpkb | 0.95.6 | All | All | All |
| Application | Aphpkb | Aphpkb | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/101466 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Andy's PHP Knowledgebase / Code / Commit [r91] | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Security Advisory SA56228 - Andy's PHP Knowledgebase Multiple Cross-Site Scripting Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| aphpkb: Release of Aphpkb 0.95.8 | af854a3a-2127-422b-91ae-364da2661108 | aphpkb.blogspot.dk | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.