CVE-2002-1922: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.
Affected Software
11 affected components
Jelsoft vBulletin=2.0_rc2
Jelsoft vBulletin=2.0_rc3
Jelsoft vBulletin=2.2.0
Jelsoft vBulletin=2.2.1
Jelsoft vBulletin=2.2.2
Jelsoft vBulletin=2.2.3
Jelsoft vBulletin=2.2.4
Jelsoft vBulletin=2.2.5
Jelsoft vBulletin=2.2.6
Jelsoft vBulletin=2.2.7
Jelsoft vBulletin=2.2.8
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jun 28, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1922?
CVE-2002-1922 has a medium severity rating due to its cross-site scripting vulnerabilities.
2
How do I fix CVE-2002-1922?
To fix CVE-2002-1922, upgrade vBulletin to a version later than 2.2.8 which addresses this vulnerability.
3
Who is affected by CVE-2002-1922?
CVE-2002-1922 affects vBulletin versions 2.0.0 through 2.2.8.
4
What type of vulnerability is CVE-2002-1922?
CVE-2002-1922 is a cross-site scripting (XSS) vulnerability.
5
What variables are involved in CVE-2002-1922?
CVE-2002-1922 involves injection via the $scriptpath and $url variables in global.php.