Back
CVE-2002-0958
Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.
Published: Oct 4, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| ekilat_llc | php\(reactor\) | 1.2.7 |
GitHub Security Advisory GHSA-36qm-778g-vmx5
Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0034.html
- http://sourceforge.net/project/shownotes.php?release_id=91877
- http://www.iss.net/security_center/static/9280.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4952 Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0034.html
- http://sourceforge.net/project/shownotes.php?release_id=91877
- http://www.iss.net/security_center/static/9280.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4952 Patch, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.59%
Top 27% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub