7.5
CVSSv2

CVE-2002-0413

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in ReBB allows remote malicious users to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

Vulnerable Product Search on Vulmon Subscribe to Product

rebb rebb 1.0

Exploits

source: wwwsecurityfocuscom/bid/4220/info ReBB is web forum software which will run on most Unix and Linux variants, as well as Microsoft Windows operating systems It is written in PHP and may be back-ended by a number of databases ReBB allows users to include images in forum messages using image tags, with the following syntax: [img] ...