4.3
CVSSv2

CVE-2002-1494

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote malicious users to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.

Vulnerable Product Search on Vulmon Subscribe to Product

aestiva html os 2.4

Exploits

source: wwwsecurityfocuscom/bid/5618/info Aestiva HTML/OS is a database engine and development suite for building websites and web-based software products HTML/OS does not sufficiently sanitize metacharacters from error message output In particular, attackers may inject HTML into error pages It is possible to create a malicious link ...