CVE-2002-2255: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the searchusername parameter in searchuser mode.
Affected Software
1 affected component
phpBB phpbb=2.0.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 15, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2255?
CVE-2002-2255 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-2255?
To mitigate CVE-2002-2255, upgrade phpBB to version 2.0.4 or later, which addresses the vulnerability.
3
Who is affected by CVE-2002-2255?
CVE-2002-2255 affects users of phpBB version 2.0.3 and possibly earlier versions.
4
What is the nature of CVE-2002-2255?
CVE-2002-2255 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts into web pages.
5
When was CVE-2002-2255 disclosed?
CVE-2002-2255 was disclosed in December 2002.