CVE
- Id
- 6617
- CVE No.
- CVE-2002-2235
- Status
- Candidate
- Description
- member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
- Phase
- Assigned (20071014)
- Votes
- None (candidate not yet proposed)
- Comments