Back

CVE-2002-0257

Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.

Published: May 29, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
apache http_server 1.3.17
apache http_server 1.3.18
apache http_server 1.3.19
apache http_server 1.3.20
apache http_server 1.3.22
usanet_creations makebid_auction_deluxe 3.30

GitHub Security Advisory GHSA-cp75-277r-65xg

Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.21%

Top 10% most likely to be exploited

Threat Score 31.3 / 100

Data Sources

NVD EPSS GitHub