{"api_version":"1","generated_at":"2026-07-23T08:09:18+00:00","cve":"CVE-2002-0257","urls":{"html":"https://cve.report/CVE-2002-0257","api":"https://cve.report/api/cve/CVE-2002-0257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0257"},"summary":{"title":"CVE-2002-0257","description":"Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-05-29 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.iss.net/security_center/static/8161.php","name":"http://www.iss.net/security_center/static/8161.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: makebid-description-css (8161): MakeBid Auction description field allows cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4069","name":"http://www.securityfocus.com/bid/4069","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"MakeBid Auction Deluxe Cross-Agent Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html","name":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USANet Creations Discussion Forums - Software Security Update/Fix","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=101328880521775&w=2","name":"http://marc.info/?l=bugtraq&m=101328880521775&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Account theft vulnerability in MakeBid Auction Deluxe 3.30' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"1.3.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"1.3.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"1.3.19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"1.3.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"http_server","cpe6":"1.3.22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"257","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"usanet_creations","cpe5":"makebid_auction_deluxe","cpe6":"3.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:42:28.550Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html"},{"name":"20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101328880521775&w=2"},{"name":"makebid-description-css(8161)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8161.php"},{"name":"4069","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4069"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-02-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html"},{"name":"20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101328880521775&w=2"},{"name":"makebid-description-css(8161)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8161.php"},{"name":"4069","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4069"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0257","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html","refsource":"CONFIRM","url":"http://www.netcreations.addr.com/dcforum/DCForumID2/126.html"},{"name":"20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101328880521775&w=2"},{"name":"makebid-description-css(8161)","refsource":"XF","url":"http://www.iss.net/security_center/static/8161.php"},{"name":"4069","refsource":"BID","url":"http://www.securityfocus.com/bid/4069"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0257","datePublished":"2002-05-03T04:00:00.000Z","dateReserved":"2002-05-01T00:00:00.000Z","dateUpdated":"2024-08-08T02:42:28.550Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-05-29 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:1.3.17:*:*:*:*:*:*:*","matchCriteriaId":"0A80B17D-FD66-40BD-9ADC-FE7A3944A696"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:1.3.18:*:*:*:*:*:*:*","matchCriteriaId":"713ADED4-CBE5-40C3-A128-99CFABF24560"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:1.3.19:*:*:*:*:*:*:*","matchCriteriaId":"70FA0B8E-1A90-4939-871A-38B9E93BCCC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:1.3.20:*:*:*:*:*:*:*","matchCriteriaId":"83BDEAE5-29B9-48E3-93FA-F30832044C9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:1.3.22:*:*:*:*:*:*:*","matchCriteriaId":"A2720E06-1B0E-4BFE-8C85-A17E597BB151"},{"vulnerable":true,"criteria":"cpe:2.3:a:usanet_creations:makebid_auction_deluxe:3.30:*:*:*:*:*:*:*","matchCriteriaId":"C9AE346F-60CA-4B6F-A627-423FBF555460"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"257","Ordinal":"1","Title":"CVE-2002-0257","CVE":"CVE-2002-0257","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"257","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.","Type":"Description","Title":"CVE-2002-0257"},{"CveYear":"2002","CveId":"257","Ordinal":"2","NoteData":"2002-05-03","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"257","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}