4.3
CVSSv2

CVE-2002-2192

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote malicious users to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.

Vulnerable Product Search on Vulmon Subscribe to Product

perception liteserve 2.0.1

Exploits

source: wwwsecurityfocuscom/bid/6143/info A cross site scripting vulnerability has been discovered in Perception LiteServe It has been reported that LiteServe fails to sanitize query strings from indexed folders It is possible for an attacker to exploit this issue by constructing a malicious link, containing encoded HTML and script cod ...
source: wwwsecurityfocuscom/bid/6131/info A cross site scripting vulnerability has been discovered in Perception LiteServe It should be noted that this vulnerability is limited to server configurations with Wildcard DNS enabled It has been reported that LiteServe fails to sanitize requested hostnames when Wildcard DNS is used This iss ...