CVE-2002-0962

GeekLog < 1.3.5 - Cross-Site Scripting via Calendar Event Link, Topic Parameter, or Comment Title

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2002-0962. PoCs published by Ahmet Sabri ALPER.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Geeklog by injecting malicious script code into URL parameters, which can steal cookie-based authentication credentials.

Description

Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, (2) the topic parameter in index.php, or (3) the title parameter in comment.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Ahmet Sabri ALPER · textwebappsphp
https://www.exploit-db.com/exploits/21525

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Geeklog by injecting malicious script code into URL parameters, which can steal cookie-based authentication credentials.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Geeklog 1.3.5 and earlier
No auth needed
Prerequisites: A victim must click on a malicious link
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Ahmet Sabri ALPER · textwebappsphp
https://www.exploit-db.com/exploits/21528

The provided text describes a cross-site scripting (XSS) vulnerability in Geeklog due to insufficient sanitization of script code in form fields. It includes an example payload demonstrating how attacker-supplied script code could be executed in the context of the website.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Geeklog (version not specified)
No auth needed
Prerequisites: Access to a form field in Geeklog that does not sanitize input
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9310.php
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9309.php
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-06/0058.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4969
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4974

Scores

EPSS 0.0860
EPSS Percentile 94.4%

Details

Status published
Products (1)
geeklog/geeklog < 1.3.5
Published Oct 04, 2002
Tracked Since Feb 18, 2026