7.5
CVSSv2

CVE-2002-0959

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote malicious users to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.

Vulnerable Product Search on Vulmon Subscribe to Product

splatt splatt forum 3.0

Exploits

source: wwwsecurityfocuscom/bid/4953/info Splatt Forum does not filter HTML from image tags This may allow an attacker to inject arbitrary script code in forum messages Injected script code will be executed in the browser of an arbitrary web user who views the malicious forum message, in the context of the website running Splatt Forum ...