20020909 phpGB: cross site scripting bugmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-09/0069.html CVE-2002-1480
phpGB 1.1 - HTML Injection
Record summary
CVE-2002-1480 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBphpGB 1.1 - HTML InjectionExploitDB exploitby ppp-designNot analyzed1 file
References
4phpgb-entry-deletion-xss(10060)vdb entry
http://www.iss.net/security_center/static/10060.php 5676vdb entry
http://www.securityfocus.com/bid/5676 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1480