6.8
CVE-2002-1168
- EPSS 1.64%
- Veröffentlicht 04.11.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:52
- Erkennungen
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Caching Proxy Server Version 3.6
Ibm ≫ Websphere Caching Proxy Server Version 4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.64% | 0.732 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://www.iss.net/security_center/static/10454.php
http://www.securityfocus.com/bid/6001