6.8
CVSSv2

CVE-2003-0154

Published: 02/04/2003 Updated: 18/10/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote malicious users to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bonsai 1.3

Vendor Advisories

Rémi Perrot fixed several security related bugs in the bonsai, the Mozilla CVS query tool by web interface Vulnerabilities include arbitrary code execution, cross-site scripting and access to configuration parameters The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2003-0152 - Remote execution of arbitrar ...

Exploits

source: wwwsecurityfocuscom/bid/5516/info Multiple cross site scripting vulnerabilities have been reported for the Bonsai tool An attacker may exploit this vulnerability by causing a victim user to follow a malicious link Attacker-supplied code may execute within the context of the site hosting the vulnerable software when the malicio ...