Back to Database
Status published
Unknown
CVE-2023-36163
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a...
Vulnerability Description
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-36163
Credits & Attribution
No credits recorded in the NVD database.
References
- https://afula.libraries.co.il/BuildaGate5library/general2/company_search_tree.php?mc=0
- http://www.levi-coins.co.il/BuildaGate5/general2/company_search_tree.php?SiteName=levicoins
- http://www.misdar-jabo.org/BuildaGate5/general2/company_search_tree.php?NewNameMade=0&SiteName=misdar&lan=en&EnterDefault=&Referral=tree&BuyerID=104732450&Clubtmp1=&SearchTop=
- https://github.com/TraiLeR2?tab=overview&from=2023-05-01&to=2023-05-31
- http://packetstormsecurity.com/files/173366/BuildaGate5-Cross-Site-Scripting.html
More from n/a
View All →CVE-2025-9910
Versions of the package jsondiffpatch before 0.7.2 are vulnerable to...
Low
2.3
CVE-2025-9802
RemoteClinic profile.php sql injection
Medium
5.1
CVE-2025-9799
Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
Low
2.3
CVE-2025-9775
RemoteClinic edit-my-profile.php unrestricted upload
Medium
6.9
CVE-2025-9774
RemoteClinic edit-patient.php information disclosure
Medium
5.3
Affected Vendor
Affected Software
Unknown
Vulnerable Versions:
Unknown
Timeline
Official Publish:
July 11th, 2023
Last Modified:
February 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.