Back
CVE-2002-0326
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.
Published: Jun 25, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| working_resources_inc. | badblue | 1.2.7 |
| working_resources_inc. | badblue | 1.2.8 |
| working_resources_inc. | badblue | 1.5 |
| working_resources_inc. | badblue | 1.5.6_beta |
| working_resources_inc. | badblue | 1.6.1_beta |
GitHub Security Advisory GHSA-5pwc-76rr-qpjq
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to...
References (6)
- http://marc.info/?l=bugtraq&m=101474387016066&w=2
- http://www.iss.net/security_center/static/8294.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4180 Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=101474387016066&w=2
- http://www.iss.net/security_center/static/8294.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4180 Patch, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.61%
Top 26% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub