Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026
CVE-2002-0475
CVE-2002-0475
Description
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.
Affected products
8cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb:1.4.4:*:*:*:*:*:*:*
- (no CPE)range: <=1.4.4
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.iss.net/security_center/static/7459.phpnvdVendor Advisory
- www.securityfocus.com/bid/4379nvdVendor Advisory
- www.securiteam.com/unixfocus/6W00Q202UM.htmlnvd
News mentions
0No linked articles in our index yet.