7.5
CVSSv2

CVE-2002-0681

Published: 23/07/2002 Updated: 20/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote malicious users to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.

Vulnerable Product Search on Vulmon Subscribe to Product

goahead software goahead webserver 2.1.5

goahead software goahead webserver 2.1.3

goahead software goahead webserver 2.1.4

goahead software goahead webserver 2.1.1

goahead software goahead webserver 2.1.2

Exploits

source: wwwsecurityfocuscom/bid/5198/info A vulnerability has been reported for GoAhead WebServer 21 Reportedly, it is possible for attackers to launch cross site scripting attacks against vulnerable systems GoAhead WebServer includes unsanitized requested URLs when displaying a 404 error page An attacker may be able to trick a user ...