First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =1.40 | |
Yabb | =1.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1845 is classified as a moderate severity vulnerability due to its potential to allow for arbitrary script injection.
To fix CVE-2002-1845, upgrade to a patched version of YaBB beyond 1.41 to eliminate the cross-site scripting vulnerability.
CVE-2002-1845 affects YaBB versions 1.40 and 1.41.
CVE-2002-1845 can be exploited for cross-site scripting attacks, potentially leading to data theft or session hijacking.
Yes, CVE-2002-1845 arises from the inability to properly sanitize user input in the password parameter.