Vulnerability Name: | CVE-2002-0682 (CCN-9520) | ||||||||
Assigned: | 2002-07-10 | ||||||||
Published: | 2002-07-10 | ||||||||
Updated: | 2019-03-25 | ||||||||
Summary: | Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: VULNWATCH Type: Patch, Vendor Advisory 20020710 [VulnWatch] wp-02-0008: Apache Tomcat Cross Site Scripting Source: MITRE Type: CNA CVE-2002-0682 Source: CCN Type: The Jakarta Project Web site Apache Tomcat Source: BUGTRAQ Type: UNKNOWN 20020710 wp-02-0008: Apache Tomcat Cross Site Scripting Source: OSVDB Type: UNKNOWN 4973 Source: CCN Type: OSVDB ID: 4973 Apache Tomcat servlet Mapping XSS Source: BID Type: UNKNOWN 5193 Source: CCN Type: BID-5193 Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability Source: CCN Type: BID-5194 Apache Tomcat DOS Device Name Cross Site Scripting Vulnerability Source: CCN Type: Westpoint Security Advisory wp-02-0008 Apache Tomcat Cross Site Scripting Source: XF Type: UNKNOWN tomcat-servlet-xss(9520) Source: XF Type: UNKNOWN tomcat-servlet-xss(9520) Source: MLIST Type: UNKNOWN [tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/ Source: MLIST Type: UNKNOWN [tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/ Source: MLIST Type: UNKNOWN [tomcat-dev] 20200213 svn commit: r1873980 [24/34] - /tomcat/site/trunk/docs/ | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |