4.3
CVSSv2

CVE-2002-2171

Published: 31/12/2002 Updated: 10/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote malicious users to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

andrey cherezov acweb 1.8

andrey cherezov acweb 1.14

Exploits

source: wwwsecurityfocuscom/bid/5793/info acWEB is prone to cross-site scripting attacks It is possible to construct a malicious link to the web server which contains arbitrary script code When the link is visited, the script code will be executed in the web client of the user visiting the link The code will be executed in the context ...