CVE-2002-2364: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.
Affected Software
1 affected component
Sourceforge Php Ticket<=0.5
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 29, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2364?
CVE-2002-2364 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-2364?
To fix CVE-2002-2364, you should upgrade to a version of PHP Ticket later than 0.5 that is not affected by the vulnerability.
3
What types of attacks are possible with CVE-2002-2364?
CVE-2002-2364 allows attackers to perform cross-site scripting attacks, which can lead to the injection of malicious scripts or HTML.
4
Which versions of PHP Ticket are affected by CVE-2002-2364?
CVE-2002-2364 affects PHP Ticket version 0.5 and earlier versions.
5
Can CVE-2002-2364 affect my web application?
If you are using PHP Ticket version 0.5 or earlier, your web application is vulnerable to CVE-2002-2364.