{"api_version":"1","generated_at":"2026-07-23T04:58:41+00:00","cve":"CVE-2003-1277","urls":{"html":"https://cve.report/CVE-2003-1277","api":"https://cve.report/api/cve/CVE-2003-1277.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1277","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1277"},"summary":{"title":"CVE-2003-1277","description":"Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.iss.net/security_center/static/10990.php","name":"http://www.iss.net/security_center/static/10990.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:yabb-se-index-xss(10990): YaBB SE index.php cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10989.php","name":"http://www.iss.net/security_center/static/10989.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:yabb-newstemplate-xss(10989): YaBB SE news_template.php cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securiteam.com/unixfocus/5BP051F8VE.html","name":"http://www.securiteam.com/unixfocus/5BP051F8VE.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"'Yabbse XSS Vulnerability in news_template.php (threadid, msgid)' - SecuriTeam","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securiteam.com/unixfocus/5BP061F8US.html","name":"http://www.securiteam.com/unixfocus/5BP061F8US.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"'Yabbse XSS Vulnerability in news_template.php' - SecuriTeam","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1277","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1277","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yabb","cpe5":"yabb","cpe6":"1.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:19:46.100Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"yabb-se-index-xss(10990)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10990.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securiteam.com/unixfocus/5BP061F8US.html"},{"name":"yabb-newstemplate-xss(10989)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10989.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securiteam.com/unixfocus/5BP051F8VE.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html"}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-16T07:37:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"yabb-se-index-xss(10990)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10990.php"},{"tags":["x_refsource_MISC"],"url":"http://www.securiteam.com/unixfocus/5BP061F8US.html"},{"name":"yabb-newstemplate-xss(10989)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10989.php"},{"tags":["x_refsource_MISC"],"url":"http://www.securiteam.com/unixfocus/5BP051F8VE.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1277","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"yabb-se-index-xss(10990)","refsource":"XF","url":"http://www.iss.net/security_center/static/10990.php"},{"name":"http://www.securiteam.com/unixfocus/5BP061F8US.html","refsource":"MISC","url":"http://www.securiteam.com/unixfocus/5BP061F8US.html"},{"name":"yabb-newstemplate-xss(10989)","refsource":"XF","url":"http://www.iss.net/security_center/static/10989.php"},{"name":"http://www.securiteam.com/unixfocus/5BP051F8VE.html","refsource":"MISC","url":"http://www.securiteam.com/unixfocus/5BP051F8VE.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1277","datePublished":"2005-11-16T07:37:00.000Z","dateReserved":"2005-11-16T00:00:00.000Z","dateUpdated":"2024-09-16T20:07:14.828Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yabb:yabb:1.5.0:*:*:*:*:*:*:*","matchCriteriaId":"161BA923-E1EC-4985-AB01-BC17FE9F3C78"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1277","Ordinal":"1","Title":"CVE-2003-1277","CVE":"CVE-2003-1277","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1277","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html","Type":"Description","Title":"CVE-2003-1277"},{"CveYear":"2003","CveId":"1277","Ordinal":"2","NoteData":"2005-11-16","Type":"Other","Title":"Published"}]}}}