CVE-2002-2129
MEDIUM 4.3EPSS 3.6%
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 3.61% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2005-11-16
- Updated
- 2024-08-08