First published: Tue Jun 11 2002(Updated: )
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =1.2.1 | |
Phpbb Group Phpbb | =1.4.1 | |
Phpbb Group Phpbb | =1.4.4 | |
Phpbb Group Phpbb | =1.4.2 | |
Phpbb Group Phpbb | =1.0.0 | |
Phpbb Group Phpbb | =1.2.0 | |
Phpbb Group Phpbb | =1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0475 is considered a medium severity vulnerability due to its ability to allow remote attackers to execute arbitrary JavaScript on client browsers.
To mitigate CVE-2002-0475, upgrade phpBB to version 1.4.5 or later, which includes fixes for this cross-site scripting vulnerability.
CVE-2002-0475 affects phpBB versions 1.4.4 and earlier, including all 1.4.x versions below 1.4.5.
CVE-2002-0475 can be exploited through cross-site scripting attacks where an attacker embeds malicious JavaScript within an IMG tag.
Users of vulnerable phpBB forums can be impacted by CVE-2002-0475, as their web browsers may execute arbitrary scripts from untrusted sources.