Description
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
Products
- phpBB Group phpBB 2.0.0
- phpBB Group phpBB 2.0 Beta 1
- phpBB Group phpBB 2.0 RC1
- phpBB Group phpBB 2.0 RC2
- phpBB Group phpBB 2.0 RC3
- phpBB Group phpBB 2.0 RC4
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-2002-0902, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2002-0902 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
- Check out the advisory links provided below.
References