CVE-2002-1678: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.
Affected Software
7 affected components
Jelsoft vBulletin=2.2.0
Jelsoft vBulletin=2.0_rc2
Jelsoft vBulletin=2.0_rc3
Jelsoft vBulletin=2.2.1
Jelsoft vBulletin=2.2.4
Jelsoft vBulletin=2.2.2
Jelsoft vBulletin=2.2.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1678?
CVE-2002-1678 has a high severity due to its potential to allow remote attackers to steal user credentials.
2
How do I fix CVE-2002-1678?
To fix CVE-2002-1678, you should upgrade to a patched version of Jelsoft vBulletin that addresses this vulnerability.
3
What versions of vBulletin are affected by CVE-2002-1678?
CVE-2002-1678 affects Jelsoft vBulletin versions 2.0 rc2 through 2.2.4.
4
What kind of attack does CVE-2002-1678 enable?
CVE-2002-1678 enables cross-site scripting (XSS) attacks that can lead to credential theft.
5
Can CVE-2002-1678 affect website security?
Yes, CVE-2002-1678 poses a significant risk to website security by allowing attackers to exploit vulnerabilities in user authentication.