VulnerabilityModified
CVE-2002-0316
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.
HIGH 7.5EPSS 8.74%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.74% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- xmb software/xmb forum
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101447886404876&w=2
- http://www.iss.net/security_center/static/8262.php
- http://www.securityfocus.com/bid/4167Exploit, Patch, Vendor Advisory
- https://docs.xmbforum2.com/index.php?title=Security_Issue_History
- http://marc.info/?l=bugtraq&m=101447886404876&w=2
- http://www.iss.net/security_center/static/8262.php
- http://www.securityfocus.com/bid/4167Exploit, Patch, Vendor Advisory
- https://docs.xmbforum2.com/index.php?title=Security_Issue_History
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.