Back

CVE-2002-2391

SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (2)

Vendor Product Version
webchat.org webchat 1.5
xoops xoops 1.0

GitHub Security Advisory GHSA-jx9c-x6x6-hq5m

SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.15%

Top 36% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub