First published: Fri May 03 2002(Updated: )
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xoops Xm Memberstats | =1.0_rc1 | |
Xoops | =1.0_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0217 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2002-0217, upgrade to a newer version of XOOPS that has addressed this cross-site scripting vulnerability.
CVE-2002-0217 can be exploited through the Title field and image field in the Private Message System.
Users of XOOPS 1.0 RC1 are affected by CVE-2002-0217 and are at risk of cross-site scripting attacks.
Exploiting CVE-2002-0217 may allow attackers to execute malicious JavaScript on victims' browsers.