4.3
CVSSv2

CVE-2003-1278

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote malicious users to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infopop opentopic 2.3.1

Exploits

source: wwwsecurityfocuscom/bid/6523/info A HTML injection vulnerability has been reported for OpenTopic The vulnerability exists because OpenTopic does not sufficiently sanitize HTML code from private message posts When a victim user views any private messages, any malicious HTML code will be executed in the web browser in the securit ...