7.5
CVE-2002-0205
- EPSS 1.59%
- Veröffentlicht 16.05.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:59
- Erkennungen
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plumtree ≫ Plumtree Corporate Portal Version 3.5
Plumtree ≫ Plumtree Corporate Portal Version 4.0
Plumtree ≫ Plumtree Corporate Portal Version 4.0_sp1
Plumtree ≫ Plumtree Corporate Portal Version 4.0i
Plumtree ≫ Plumtree Corporate Portal Version 4.0i_sp1
Plumtree ≫ Plumtree Corporate Portal Version 4.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.59% | 0.724 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=101189911121808&w=2
http://online.securityfocus.com/archive/82/248396
http://www.iss.net/security_center/static/7817.php
http://www.securityfocus.com/bid/3799