CVE-2002-2235
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
Scoring
- CVSS base score
- 0.03
- EPSS probability
- 0.55%
- Published
- 2007-10-14
- Last modified
- 2026-03-16
Affected products
- n/a n/a