First published: Tue Jun 11 2002(Updated: )
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.71 | |
PostBoard | =2.0.1 | |
Postnuke Software Foundation Pnphpbb | =0.64 | |
Postnuke Software Foundation Pnphpbb | =0.703 | |
PostBoard | =2.0 | |
Postnuke Software Foundation Pnphpbb | =0.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0535 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2002-0535, ensure that you upgrade to PostBoard versions later than 2.0.1 which contain security patches.
The affected versions of PostBoard in CVE-2002-0535 are 2.0.1 and earlier.
Yes, CVE-2002-0535 can potentially compromise user data by executing malicious scripts in the context of other users.
CVE-2002-0535 is associated with cross-site scripting (XSS) attacks.