4.3
CVSSv2

CVE-2002-1445

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote malicious users to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.

Vulnerable Product Search on Vulmon Subscribe to Product

w3c cern httpd 3.0

Exploits

source: wwwsecurityfocuscom/bid/5447/info CERN httpd is a freely available HTTP server and HTTP proxy server available from the W3C The httpd Proxy is vulnerable to a cross site scripting attack The condition is present because of the way URLS are displayed in error messages It is possible for arbitrary HTML or script code to be embe ...