Back to Database
Status published
Medium
CVE-2001-0897
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before...
Vulnerability Description
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2001-0897
Credits & Attribution
No credits recorded in the NVD database.
References
More from infopop
View All →CVE-2022-25091
Infopop Ultimate Bulletin Board up to v5.47a was discovered to...
Unknown
0
CVE-2005-1199
SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers...
High
7.5
CVE-2003-1278
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers...
Medium
4.3
CVE-2003-0587
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB)...
Medium
6.9
CVE-2002-0223
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through...
High
7.5
Affected Vendor
infopop
View all reports →Affected Software
ultimate bulletin board
Vulnerable Versions:
1.0, 2.0, 2.01, 2.02, 2.03, 2.04, 2.05, 2.10, 2.11, 3.0, 3.01, 3.02, 3.5, 3.6, 3.7, 3.75, 4.0, 4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.50, 4.51, 4.52, 4.53, 4.75, 4.80, 4.81, 4.82, 4.83, 4.84, 4.85, 4.86, 5.00, 5.01, 5.02, 5.05, 5.06, 5.07, 5.08, 5.09, 5.10, 5.11, 5.12, 5.13, 5.14, 5.15, 5.16, 5.17, 5.18, 5.19, 5.20, 5.25, 5.26, 5.27, 5.28, 5.29, 5.30, 5.31, 5.32, 5.33, 5.34, 5.35, 5.36, 5.37, 5.38, 5.39, 5.40, 5.41, 5.42, 5.43, 5.44, 5.45, 5.46, 5.47
Timeline
Official Publish:
February 2nd, 2002
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.