7.5
CVSSv2

CVE-2002-0902

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote malicious users to execute Javascript as other phpBB users by including a and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0_rc1

phpbb group phpbb 2.0_rc3

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0_beta1

phpbb group phpbb 2.0_rc2

phpbb group phpbb 2.0_rc4

Exploits

source: wwwsecurityfocuscom/bid/4858/info It is possible to inject arbitrary HTML into phpBB2 forum messages via the use of BBCode image tags A similar issue is described in Bugtraq ID 4379 "PHPBB Image Tag User-Embedded Scripting Vulnerability" However, phpBB2 was found to not be vulnerable to this previous issue A double-quotation ...