PT-2002-1912 · Phpbb · Phpbb

Published

2002-08-31

·

Updated

2008-09-05

·

CVE-2002-0902

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpBB version 2.0.0
Description: The issue allows remote attackers to execute Javascript as other phpBB users. This is achieved by including a http:// and a double-quote (") in the [IMG] tag, which bypasses the security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
Recommendations: For phpBB version 2.0.0, update to a newer version that addresses this issue to prevent remote attackers from executing Javascript as other phpBB users.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0902

Affected Products

Phpbb