peter bassill · operator
$ cve CVE-2002-1708 JSON

CVE-2002-1708 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.3% (pctl 91)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.26% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
basilixbasilix webmail

Public exploits

SourceTitleDate
exploit-dbBasiliX Webmail 1.1 - Message Content Script Injection2002-06-19

References

→ the Explorer  ·  watch your stack  ·  NVD