5
CVE-2002-1348
- EPSS 2.03%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:59:08
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.03% | 0.785 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://www.debian.org/security/2003/dsa-249
http://www.debian.org/security/2003/dsa-250
http://www.debian.org/security/2003/dsa-251
http://www.redhat.com/support/errata/RHSA-2003-044.html
http://www.redhat.com/support/errata/RHSA-2003-045.html
http://marc.info/?l=bugtraq&m=104552193927323&w=2
http://sourceforge.net/project/shownotes.php?release_id=126233
http://www.iss.net/security_center/static/11266.php
http://www.securityfocus.com/bid/6794