CVE-2002-1845: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.
Affected Software
2 affected components
Yabb Yabb=1.40
Yabb Yabb=1.41
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1845?
CVE-2002-1845 is classified as a moderate severity vulnerability due to its potential to allow for arbitrary script injection.
2
How do I fix CVE-2002-1845?
To fix CVE-2002-1845, upgrade to a patched version of YaBB beyond 1.41 to eliminate the cross-site scripting vulnerability.
3
What versions of YaBB are affected by CVE-2002-1845?
CVE-2002-1845 affects YaBB versions 1.40 and 1.41.
4
What kind of attack can CVE-2002-1845 be used for?
CVE-2002-1845 can be exploited for cross-site scripting attacks, potentially leading to data theft or session hijacking.
5
Is CVE-2002-1845 related to user input?
Yes, CVE-2002-1845 arises from the inability to properly sanitize user input in the password parameter.