CVE-2002-2362: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in formheader.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.
Affected Software
1 affected component
Sourceforge Mymarket=1.71
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 29, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2362?
CVE-2002-2362 has a moderate severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-2362?
To fix CVE-2002-2362, you should sanitize and validate the user input for the noticemsg parameter in form_header.php.
3
Who is affected by CVE-2002-2362?
CVE-2002-2362 affects users of MyMarket version 1.71.
4
What type of attacks can be executed via CVE-2002-2362?
CVE-2002-2362 allows remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.
5
Is CVE-2002-2362 exploitable without authentication?
Yes, CVE-2002-2362 can be exploited by remote attackers without needing authentication.