peter bassill · operator
$ cve CVE-2002-2424 JSON

CVE-2002-2424 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.4% (pctl 73)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.45% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
ekilat llcphp\(reactor\)

Public exploits

SourceTitleDate
exploit-dbPHPReactor 1.2.7 - Style Attribute HTML Injection2002-08-24

References

→ the Explorer  ·  watch your stack  ·  NVD