Back
CVE-2002-0458
Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.
Published: Aug 12, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| linux-sottises | news-tnk | * |
GitHub Security Advisory GHSA-8qmr-h95w-97h2
Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to...
References (10)
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0206.html Vendor Advisory
- http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools
- http://www.iss.net/security_center/static/8477.php Patch, Vendor Advisory
- http://www.linux-sottises.net/software/news-tnk/CHANGES
- http://www.securityfocus.com/bid/14145
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0206.html Vendor Advisory
- http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools
- http://www.iss.net/security_center/static/8477.php Patch, Vendor Advisory
- http://www.linux-sottises.net/software/news-tnk/CHANGES
- http://www.securityfocus.com/bid/14145
Risk Scores
CVSS Score
7.6 / 10
EPSS Score
2.19%
Top 19% most likely to be exploited
Threat Score
31.1 / 100
Data Sources
NVD
EPSS
GitHub