7.5
CVSSv2

CVE-2002-0787

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote malicious users to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

critical path injoin directory server 4.0

Exploits

source: wwwsecurityfocuscom/bid/4717/info Critical Path provides an LDAP (Lightweight Directory Access Protocol) Directory Server called InJoin InJoin Directory is provided for Microsoft Windows operating systems and Unix variants HTML code is not filtered from URL parameters that are used as output in the web-based administrative inte ...