Back

CVE-2002-2319

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
mysimplenews mysimplenews 1.0

GitHub Security Advisory GHSA-gqjj-vwj4-p2mg

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.25%

Top 19% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub