Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2002-08-31T04:00:00

Updated: 2002-09-10T09:00:00

Reserved: 2002-08-16T00:00:00


Link: CVE-2002-0902

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2002-10-04T04:00:00.000

Modified: 2008-09-05T20:29:15.490


Link: CVE-2002-0902

JSON object: View

cve-icon Redhat Information

No data.