CVE
- Id
- 3703
- CVE No.
- CVE-2001-0897
- Status
- Candidate
- Description
- Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Armstrong, Foat, Wall
- Comments
- Frech> XF:ultimatebb-cookie-gain-privileges(6142) | Is this a variant of the following references: | BugTraq Mailing List, Wed Feb 21 2001 13:19:16 Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164583 | BugTraq Mailing List, Wed Feb 21 2001 17:59:13 Re: Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164716