CVE-2002-0902: High severity Phpbb Group Phpbb vulnerability
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0902?
The severity of CVE-2002-0902 is classified as moderate, due to the risk of cross-site scripting attacks.
How do I fix CVE-2002-0902?
To fix CVE-2002-0902, upgrade to phpBB version 2.0.1 or later, which addresses this vulnerability.
What systems are affected by CVE-2002-0902?
CVE-2002-0902 affects phpBB versions 2.0.0, 2.0_rc1, 2.0_rc2, 2.0_rc3, and 2.0_rc4.
What type of attack does CVE-2002-0902 allow?
CVE-2002-0902 allows remote attackers to execute JavaScript in the context of another user's session, leading to potential data theft or session hijacking.
How can I detect if my system is vulnerable to CVE-2002-0902?
You can detect vulnerability to CVE-2002-0902 by checking your phpBB version and reviewing log files for unusual script executions.