ID

VAR-200212-0577


CVE

CVE-2002-1702


TITLE

PHP Classifieds Cross-Site Scripting Vulnerability

Trust: 1.5

sources: CNVD: CNVD-2002-2878 // BID: 5022 // CNNVD: CNNVD-200212-834

DESCRIPTION

Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter. PHP Classifieds is a web-based directory classification program written in PHP.  PHP Classifieds lacks proper and sufficient filtering of the parameters submitted by users. An attacker can build a link containing URL parameters of malicious code. When the user views this link, the included malicious script code will be in the user's browser Execution, leading to the leakage of information based on cookie authentication

Trust: 1.71

sources: NVD: CVE-2002-1702 // CNVD: CNVD-2002-2878 // BID: 5022

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2002-2878

AFFECTED PRODUCTS

vendor:deltascriptsmodel:php classifiedsscope:eqversion:6.0.5

Trust: 1.9

vendor:nonemodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2002-2878 // BID: 5022 // CNNVD: CNNVD-200212-834 // NVD: CVE-2002-1702

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1702
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200212-834
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2002-1702
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200212-834 // NVD: CVE-2002-1702

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1702

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-834

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200212-834

EXTERNAL IDS

db:NVDid:CVE-2002-1702

Trust: 2.2

db:BIDid:5022

Trust: 1.9

db:CNVDid:CNVD-2002-2878

Trust: 0.6

db:XFid:9363

Trust: 0.6

db:NSFOCUSid:2984

Trust: 0.6

db:CNNVDid:CNNVD-200212-834

Trust: 0.6

sources: CNVD: CNVD-2002-2878 // BID: 5022 // CNNVD: CNNVD-200212-834 // NVD: CVE-2002-1702

REFERENCES

url:http://www.securityfocus.com/bid/5022

Trust: 1.6

url:http://online.securityfocus.com/archive/1/277049

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/9363

Trust: 1.0

url:http://xforce.iss.net/xforce/xfdb/9363

Trust: 0.6

url:http://www.nsfocus.net/vulndb/2984

Trust: 0.6

sources: CNNVD: CNNVD-200212-834 // NVD: CVE-2002-1702

CREDITS

§ o m e 1※ exe@FlashMail.com

Trust: 0.6

sources: CNNVD: CNNVD-200212-834

SOURCES

db:CNVDid:CNVD-2002-2878
db:BIDid:5022
db:CNNVDid:CNNVD-200212-834
db:NVDid:CVE-2002-1702

LAST UPDATE DATE

2024-08-14T13:40:32.832000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2002-2878date:2002-06-22T00:00:00
db:BIDid:5022date:2002-06-14T00:00:00
db:CNNVDid:CNNVD-200212-834date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1702date:2017-07-11T01:29:20.917

SOURCES RELEASE DATE

db:CNVDid:CNVD-2002-2878date:2002-06-14T00:00:00
db:BIDid:5022date:2002-06-14T00:00:00
db:CNNVDid:CNNVD-200212-834date:2002-06-14T00:00:00
db:NVDid:CVE-2002-1702date:2002-12-31T05:00:00