Back

CVE-2002-1845

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
yabb yabb 1.40
yabb yabb 1.41

GitHub Security Advisory GHSA-pp92-5cx8-mvc6

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 3.95%

Top 11% most likely to be exploited

Threat Score 18.4 / 100

Data Sources

NVD EPSS GitHub