7.5
CVSSv2

CVE-2001-0987

Published: 22/07/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in CGIWrap prior to 3.7 allows remote malicious users to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.

Vulnerable Product Search on Vulmon Subscribe to Product

nathan neulinger cgiwrap

Exploits

source: wwwsecurityfocuscom/bid/3081/info CGIWrap is a free, open-source program for running CGI securely CGIWrap does not filter embedded scripting commands from user-supplied input A web user may submit a malicious link into any form which displays user-supplied input, such as guestbooks, forums, etc Users clicking on the link will ...