7.5

CVE-2002-0166

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stephen TurnerAnalog Version3.90_beta1
Stephen TurnerAnalog Version3.90_beta2
Stephen TurnerAnalog Version4.1
Stephen TurnerAnalog Version4.01
Stephen TurnerAnalog Version4.02
Stephen TurnerAnalog Version4.03
Stephen TurnerAnalog Version4.04
Stephen TurnerAnalog Version4.11
Stephen TurnerAnalog Version4.14
Stephen TurnerAnalog Version4.15
Stephen TurnerAnalog Version4.16
Stephen TurnerAnalog Version4.90_beta2
Stephen TurnerAnalog Version4.90_beta3
Stephen TurnerAnalog Version4.90_beta4
Stephen TurnerAnalog Version4.91_beta1
Stephen TurnerAnalog Version5.0
Stephen TurnerAnalog Version5.01
Stephen TurnerAnalog Version5.1a
Stephen TurnerAnalog Version5.2
Stephen TurnerAnalog Version5.02
Stephen TurnerAnalog Version5.03
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.756
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc
http://www.debian.org/security/2002/dsa-125
Patch
Vendor Advisory
http://www.iss.net/security_center/static/8656.php
http://www.osvdb.org/2059
http://www.redhat.com/support/errata/RHSA-2002-059.html
http://www.securityfocus.com/bid/4389