7.5
CVSSv2

CVE-2002-0118

Published: 25/03/2002 Updated: 04/11/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote malicious users to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

infopop ultimate bulletin board 5.4.7e

infopop ultimate bulletin board 6.0

infopop ultimate bulletin board 6.0.1

infopop ultimate bulletin board 6.0.4f

infopop ultimate bulletin board 6.0beta

infopop ultimate bulletin board 5.43

infopop ultimate bulletin board 6.2.0_beta_release_1.0

infopop ultimate bulletin board 6.0.2

infopop ultimate bulletin board 6.0.3

Exploits

source: wwwsecurityfocuscom/bid/3829/info UBB (Ultimate Bulletin Board) is commercial web forums/community software that is written in Perl It runs on various Unix/Linux variants, as well as Microsoft Windows NT/2000 UBB is prone to cross-agent scripting attacks via the insertion of HTML tags into image links in messages Due to insuff ...