CVE-2002-1802: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news.
Affected Software
1 affected component
Xoops Xoops=1.0_rc3
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1802?
CVE-2002-1802 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-1802?
To fix CVE-2002-1802, it is recommended to upgrade to a non-vulnerable version of Xoops that does not include this XSS flaw.
3
What systems are affected by CVE-2002-1802?
CVE-2002-1802 specifically affects Xoops version 1.0 RC3.
4
What types of attacks can occur due to CVE-2002-1802?
CVE-2002-1802 allows remote attackers to execute arbitrary web scripts or HTML via a malicious IMG tag.
5
Who is responsible for addressing CVE-2002-1802?
It is the responsibility of the administrators running Xoops version 1.0 RC3 to address and mitigate the risks associated with CVE-2002-1802.