peter bassill · operator
$ cve CVE-2002-1829 JSON

CVE-2002-1829 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.6% (pctl 89)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.57% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
openbbopenbb

Public exploits

SourceTitleDate
exploit-dbOpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection2002-05-24

References

→ the Explorer  ·  watch your stack  ·  NVD