4.3
CVSSv2

CVE-2002-1493

Published: 02/04/2003 Updated: 10/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote malicious users to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

lycos htmlgear guestgear

Exploits

source: wwwsecurityfocuscom/bid/5728/info Lycos htmlGEAR guestGEAR does not sanitize HTML from CSS (Cascading Style-Sheets) elements in guestbook fields An attacker could capitalize on this situation to include arbitrary HTML and script code in a guestbook entries, which would be rendered in the web client of users who view the malicious ...