Lucene search

K
cve[email protected]CVE-2002-0117
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2002-0117

2002-06-2504:00:00
web.nvd.nist.gov
21
cybersecurity
xss
vulnerability
remote attack
scripts
yet another bulletin board
cookies
javascript
img tag

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.094 Low

EPSS

Percentile

94.8%

Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.

Affected configurations

NVD
Node
yabbyabbMatch0.01_releasegold
OR
yabbyabbMatch0.01_sp1gold
OR
yabbyabbMatch2000-09-01
OR
yabbyabbMatch2000-09-11

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.094 Low

EPSS

Percentile

94.8%

Related for CVE-2002-0117