Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-1700

Опубликовано: 31 дек. 2002
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.16341
Средний

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

EPSS

Процентиль: 95%
0.16341
Средний

4.3 Medium

CVSS2

Дефекты

CWE-79