CVE-2002-0962

medium

Description

Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, (2) the topic parameter in index.php, or (3) the title parameter in comment.php.

References

http://www.iss.net/security_center/static/9310.php

http://www.iss.net/security_center/static/9309.php

http://geeklog.sourceforge.net/article.php?story=20020610013358149

http://archives.neohapsis.com/archives/bugtraq/2002-06/0058.html

Details

Source: Mitre, NVD

Published: 2002-10-04

Updated: 2008-09-05

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium