4.3
CVSSv2

CVE-2002-2255

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote malicious users to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb phpbb 2.0.3

Exploits

source: wwwsecurityfocuscom/bid/6311/info phpBB is vulnerable to cross site scripting attacks This is due to insufficient santization of user-supplied input The problem is located in the searchphp script This issue may be exploited by an attacker to steal a legitimate users cookie-based authentication credentials <html> <bo ...