CVE-2002-1683: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.
Affected Software
1 affected component
Working Resources Inc. BadBlue=personal_1.7.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1683?
CVE-2002-1683 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
2
How does CVE-2002-1683 affect BadBlue Personal Edition 1.7.3?
CVE-2002-1683 allows attackers to inject arbitrary scripts into the cleanSearchString() function, affecting other users of BadBlue Personal Edition 1.7.3.
3
How do I fix CVE-2002-1683?
To fix CVE-2002-1683, upgrade to a version of BadBlue Personal Edition that does not contain this vulnerability.
4
Who is impacted by CVE-2002-1683?
Users of BadBlue Personal Edition version 1.7.3 are impacted by CVE-2002-1683.
5
What type of vulnerability is CVE-2002-1683?
CVE-2002-1683 is a cross-site scripting (XSS) vulnerability.