Back

CVE-2002-1480

Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

Published: Apr 22, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
phpgb phpgb 1.10

GitHub Security Advisory GHSA-76j9-m8j4-74fx

Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 4.27%

Top 10% most likely to be exploited

Threat Score 28.5 / 100

Data Sources

NVD EPSS GitHub