PT-2002-1912 · Phpbb · Phpbb
Published
2002-08-31
·
Updated
2008-09-05
·
CVE-2002-0902
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
phpBB version 2.0.0
Description:
The issue allows remote attackers to execute Javascript as other phpBB users. This is achieved by including a http:// and a double-quote (") in the [IMG] tag, which bypasses the security check, terminates the
src parameter of the resulting HTML IMG tag, and injects the script.Recommendations:
For phpBB version 2.0.0, update to a newer version that addresses this issue to prevent remote attackers from executing Javascript as other phpBB users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpbb