7.6

CVE-2002-0457

Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bg Guestbook ≫ Bg Guestbook Version 1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.11% 0.793
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.iss.net/security_center/static/8474.php
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/262693
Vendor Advisory
http://www.securityfocus.com/bid/4308
Patch
Vendor Advisory