Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-1168

Опубликовано: 04 нояб. 2002
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:websphere_caching_proxy_server:3.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_caching_proxy_server:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01908
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

EPSS

Процентиль: 83%
0.01908
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other