6.8
CVSSv2

CVE-2002-1006

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and previous versions allows remote malicious users to execute arbitrary web script via parserl.pl.

Vulnerable Product Search on Vulmon Subscribe to Product

bbc education betsie 1.5.10

bbc education betsie 1.5.2

bbc education betsie 1.5.9

bbc education betsie 1.5.3

bbc education betsie 1.5.4

bbc education betsie 1.5.5

bbc education betsie 1.5.6

bbc education betsie 1.5.7

bbc education betsie 1.5

bbc education betsie 1.5.1

bbc education betsie 1.5.11

bbc education betsie 1.5.8

Exploits

source: wwwsecurityfocuscom/bid/5135/info Betsie (BBC Education Text to Speech Internet Enhancer) is prone to a cross-site scripting vulnerability This issue exists in the parserlpl script Attackers may exploit this condition via a malicious link to a site running the vulnerable software Successful exploitation will enable an attacke ...