peter bassill · operator
$ cve CVE-2002-1480 JSON

CVE-2002-1480 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.3% (pctl 91)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.27% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-22
Last modified2026-06-16

Affected (1)

VendorProduct
phpgbphpgb

Public exploits

SourceTitleDate
exploit-dbphpGB 1.1 - HTML Injection2002-09-09

References

→ the Explorer  ·  watch your stack  ·  NVD