First published: Mon Mar 25 2002(Updated: )
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =0.01_release-gold | |
Yabb | =0.01_sp1-gold | |
Yabb | =2000-09-01 | |
Yabb | =2000-09-11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0117 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2002-0117, you should upgrade to a patched version of YaBB that addresses this cross-site scripting vulnerability.
CVE-2002-0117 affects users of Yet Another Bulletin Board (YaBB) versions 2000-09-11, 2000-09-01, 0.01_release-gold, and 0.01_sp1-gold.
The risks associated with CVE-2002-0117 include the potential execution of arbitrary scripts and cookie theft by remote attackers.
You can identify vulnerability to CVE-2002-0117 by checking your YaBB version and if it is one of the affected versions listed in this CVE.