← Back

CVE-2001-0897

nvd nist
Published: Nov 15, 2001Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.

Affected (110)

1 product
Ultimate Bulletin Board
Configuration A
110 vulnerable
Vulnerable SoftwareAffected Versions
Infopop
All versions
Version 1.0
Version 2.01
Version 2.02
Version 2.03
Version 2.04
Version 2.05
Version 2.0
Version 2.10
Version 2.11
Version 3.01
Version 3.02
Version 3.0
Version 3.5
Version 3.6
Version 3.75
Version 3.7
Version 4.01
Version 4.02
Version 4.03
Version 4.04
Version 4.05
Version 4.06
Version 4.07
Version 4.0
Version 4.50
Version 4.51
Version 4.52
Version 4.53
Version 4.75
Version 4.80
Version 4.81
Version 4.82
Version 4.83
Version 4.84
Version 4.85
Version 4.86
Version 5.00
Version 5.01
Version 5.02
Version 5.05
Version 5.05 a
Version 5.06
Version 5.06 a
Version 5.07
Version 5.08
Version 5.09
Version 5.10
Version 5.11
Version 5.12
Version 5.13
Version 5.14
Version 5.15
Version 5.16
Version 5.17
Version 5.18
Version 5.19
Version 5.20
Version 5.25
Version 5.26
Version 5.27
Version 5.28
Version 5.29
Version 5.29 a
Version 5.29 b
Version 5.30
Version 5.30 a
Version 5.31
Version 5.32
Version 5.33
Version 5.34
Version 5.34 a
Version 5.35
Version 5.36
Version 5.36 a
Version 5.37
Version 5.38
Version 5.38 a
Version 5.38 b
Version 5.38 c
Version 5.38 d
Version 5.39
Version 5.39 a
Version 5.39 b
Version 5.39 c
Version 5.40
Version 5.41
Version 5.41 a
Version 5.41 b
Version 5.42
Version 5.42 a
Version 5.43
Version 5.43 a
Version 5.43 b
Version 5.43 c
Version 5.43 d
Version 5.44
Version 5.44 a
Version 5.44 b
Version 5.45
Version 5.45 a
Version 5.45 b
Version 5.45 c
Version 5.46
Version 5.46 a
Version 5.47
Version 5.47 a
Version 5.47 b
Version 5.47 c
Version 5.47 d

References (4)

Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.