VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026

CVE-2002-0475

CVE-2002-0475

Description

Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.

Affected products

8
  • PhpBB/phpBB8 versions
    cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phpbb_group:phpbb:1.4.4:*:*:*:*:*:*:*
    • (no CPE)range: <=1.4.4

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.