Vulnerability Description
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Infopop | Ultimate Bulletin Board | - |
References
- http://marc.info/?l=bugtraq&m=100586033530341&w=2Mailing List
- http://marc.info/?l=bugtraq&m=100586541317940&w=2Mailing List
- http://marc.info/?l=bugtraq&m=100586033530341&w=2Mailing List
- http://marc.info/?l=bugtraq&m=100586541317940&w=2Mailing List
FAQ
What is CVE-2001-0897?
CVE-2001-0897 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror fi...
How severe is CVE-2001-0897?
CVE-2001-0897 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0897?
Check the references section above for vendor advisories and patch information. Affected products include: Infopop Ultimate Bulletin Board.