6.8
CVSSv2

CVE-2002-1480

Published: 22/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in phpGB prior to 1.20 allows remote malicious users to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgb phpgb 1.10

Exploits

source: wwwsecurityfocuscom/bid/5676/info phpGB is subject to HTML injection attacks phpGB fails to check for the presence of HTML tags when generating guestbook entries It is reported that an attacker may inject HTML and script code into guestbook entries, which will be executed in the web client of the administrative guestbook user w ...