4.3
CVSSv2

CVE-2002-2424

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote malicious users to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

Vulnerable Product Search on Vulmon Subscribe to Product

ekilat llc php\\(reactor\\) 1.27pl1

Exploits

source: wwwsecurityfocuscom/bid/5569/info php(Reactor) does not sufficiently sanitize HTML from various fields (such as in the body of a message or in profile fields) It is possible to inject arbitrary HTML and script code into these fields An attacker may potentially exploit this situation to cause arbitrary HTML and script code to ex ...