CVE-2003-1277
Summary
| CVE | CVE-2003-1277 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database:yabb-se-index-xss(10990): YaBB SE index.php cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| ISS X-Force Database:yabb-newstemplate-xss(10989): YaBB SE news_template.php cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| 'Yabbse XSS Vulnerability in news_template.php (threadid, msgid)' - SecuriTeam | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Exploit, Vendor Advisory |
| 'Yabbse XSS Vulnerability in news_template.php' - SecuriTeam | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.