5
CVSSv2

CVE-2002-1429

Published: 11/04/2003 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote malicious users to inject arbitrary HTML into the shoutbox page via the site parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

endity.com shoutbox 1.2

Exploits

source: wwwsecurityfocuscom/bid/5354/info shoutBOX does not sufficiently sanitize HTML tags from input supplied via form fields Attackers may exploit this lack of input validation to inject arbitrary HTML and script code into pages that are generated by the script This may result in execution of attacker-supplied code in the web client ...