Unrated severityNVD Advisory· Published May 16, 2002· Updated Apr 16, 2026
CVE-2002-0217
CVE-2002-0217
Description
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- online.securityfocus.com/archive/1/252828nvdExploitVendor Advisory
- www.iss.net/security_center/static/8025.phpnvdVendor Advisory
- www.iss.net/security_center/static/8030.phpnvd
- www.securityfocus.com/bid/3978nvd
- www.securityfocus.com/bid/3981nvd
News mentions
0No linked articles in our index yet.