Feed/CVE-2002-0292
CVE-2002-0292LOWCVSS 2.6

CVE-2002-0292

Published May 30, 2002·Updated Jun 16, 2026

NVD Description

Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.

CVSS Vector

AV:N/AC:H/Au:N/C:P/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free