7.5
CVE-2002-0166
- EPSS 1.41%
- Veröffentlicht 22.04.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stephen Turner ≫ Analog Version3.90_beta1
Stephen Turner ≫ Analog Version3.90_beta2
Stephen Turner ≫ Analog Version4.1
Stephen Turner ≫ Analog Version4.01
Stephen Turner ≫ Analog Version4.02
Stephen Turner ≫ Analog Version4.03
Stephen Turner ≫ Analog Version4.04
Stephen Turner ≫ Analog Version4.11
Stephen Turner ≫ Analog Version4.14
Stephen Turner ≫ Analog Version4.15
Stephen Turner ≫ Analog Version4.16
Stephen Turner ≫ Analog Version4.90_beta2
Stephen Turner ≫ Analog Version4.90_beta3
Stephen Turner ≫ Analog Version4.90_beta4
Stephen Turner ≫ Analog Version4.91_beta1
Stephen Turner ≫ Analog Version5.0
Stephen Turner ≫ Analog Version5.01
Stephen Turner ≫ Analog Version5.1a
Stephen Turner ≫ Analog Version5.2
Stephen Turner ≫ Analog Version5.02
Stephen Turner ≫ Analog Version5.03
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.787 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|