Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-08-31T04:00:00

Updated: 2024-08-08T03:03:49.271Z

Reserved: 2002-08-16T00:00:00

Link: CVE-2002-0902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2002-10-04T04:00:00.000

Modified: 2008-09-05T20:29:15.490

Link: CVE-2002-0902

cve-icon Redhat

No data.