Back

CVE-2002-0326

Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.

Published: Jun 25, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
working_resources_inc. badblue 1.2.7
working_resources_inc. badblue 1.2.8
working_resources_inc. badblue 1.5
working_resources_inc. badblue 1.5.6_beta
working_resources_inc. badblue 1.6.1_beta

GitHub Security Advisory GHSA-5pwc-76rr-qpjq

Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.61%

Top 26% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub