Back

CVE-2002-0118

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.

Published: Mar 25, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
infopop ultimate_bulletin_board 5.4.7e
infopop ultimate_bulletin_board 5.43
infopop ultimate_bulletin_board 6.0
infopop ultimate_bulletin_board 6.0.1
infopop ultimate_bulletin_board 6.0.2
infopop ultimate_bulletin_board 6.0.3
infopop ultimate_bulletin_board 6.0.4f
infopop ultimate_bulletin_board 6.0beta
infopop ultimate_bulletin_board 6.2.0_beta_release_1.0

GitHub Security Advisory GHSA-q5x4-rm4c-5c6p

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 7.10%

Top 6% most likely to be exploited

Threat Score 32.1 / 100

Data Sources

NVD EPSS GitHub