4.3
CVSSv2

CVE-2004-1442

Published: 31/12/2004 Updated: 12/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote malicious users to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

Vulnerable Product Search on Vulmon Subscribe to Product

ibm net.data 7.0

ibm net.data 7.2

Exploits

source: wwwsecurityfocuscom/bid/9488/info IBM NetData is prone to cross-site scripting attacks via error message output This may permit a remote attack to create a link to a system hosting the software that includes embedded HTML and script code This hostile code may be rendered in the web browser of a user who follows the malicious li ...