Back
CVE-2002-0117
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.
Published: Mar 25, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| yabb | yabb | 0.01_release |
| yabb | yabb | 0.01_sp1 |
| yabb | yabb | 2000-09-01 |
| yabb | yabb | 2000-09-11 |
GitHub Security Advisory GHSA-cj73-32hf-pwxx
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier...
References (10)
- http://online.securityfocus.com/archive/1/249031 Exploit, Patch, Vendor Advisory
- http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3828 Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/7840.php Patch, Vendor Advisory
- http://www.osvdb.org/2019
- http://www.yabbforum.com/
- http://online.securityfocus.com/archive/1/249031 Exploit, Patch, Vendor Advisory
- http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3828 Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/7840.php Patch, Vendor Advisory
- http://www.osvdb.org/2019
- http://www.yabbforum.com/
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.84%
Top 15% most likely to be exploited
Threat Score
30.9 / 100
Data Sources
NVD
EPSS
GitHub