4.3
CVSSv2

CVE-2002-1802

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote malicious users to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops 1.0_rc3

Exploits

source: wwwsecurityfocuscom/bid/5785/info Problems with XOOPS could make it possible to execute arbitrary script code in a vulnerable client XOOPS does not sufficiently filter potentially malicious HTML code from posted messages As a result, when a user views a message posting that contains malicious HTML code, the code contained in th ...