4.3
CVSSv2

CVE-2003-0615

Published: 27/08/2003 Updated: 03/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote malicious users to insert web script via a URL that is fed into the form's action parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cgi.pm cgi.pm 2.75

cgi.pm cgi.pm 2.751

openpkg openpkg 1.3

openpkg openpkg current

cgi.pm cgi.pm 2.753

cgi.pm cgi.pm 2.76

cgi.pm cgi.pm 2.73

cgi.pm cgi.pm 2.74

cgi.pm cgi.pm 2.93

openpkg openpkg 1.2

cgi.pm cgi.pm 2.78

cgi.pm cgi.pm 2.79

debian debian linux 3.0

Vendor Advisories

A cross-site scripting vulnerability exists in the start_form() function in CGIpm This function outputs user-controlled data into the action attribute of a form element without sanitizing it, allowing a remote user to execute arbitrary web script within the context of the generated page Any program which uses this function in the CGIpm module m ...