4.3
CVSSv2

CVE-2002-2246

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in VisNetic Website prior to 3.5.15 allows remote malicious users to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

Vulnerable Product Search on Vulmon Subscribe to Product

deerfield visnetic website

Exploits

source: wwwsecurityfocuscom/bid/6369/info A vulnerability has been discovered in VisNetic Website when generating a 404 page for a non-existent resources The issue is due to insufficient sanitization of the HTTP 'referer' header It is possible to cause arbitrary code to be executed within the context of the visited 404 page by embedding ...