CVE-2002-2386: XSS
Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS 1.0, when allowing on-line question development, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the SRC attribute of an IMG tag.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2386?
CVE-2002-2386 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2002-2386?
To fix CVE-2002-2386, you should update the XOOPS software to a version that addresses this vulnerability.
What software is affected by CVE-2002-2386?
CVE-2002-2386 affects the Quizz module for XOOPS 1.0, specifically version 1.0_rc3.
What are the implications of CVE-2002-2386 for web applications?
CVE-2002-2386 allows attackers to execute scripts in the context of a victim's browser, potentially compromising user data and sessions.
Can CVE-2002-2386 be exploited remotely?
Yes, CVE-2002-2386 can be exploited remotely by injecting malicious scripts through the Quizz module.