Vulnerability Name: | CVE-2002-2073 (CCN-8050) | ||||||||
Assigned: | 2002-01-29 | ||||||||
Published: | 2002-01-29 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-2073 Source: VULNWATCH Type: UNKNOWN 20020130 RFP2201: MS Site Server Evilness Source: CCN Type: rain forest puppy advisory RFP2201 MS Site Server Evilness Source: XF Type: UNKNOWN siteserver-asp-css(8050) Source: CCN Type: OSVDB ID: 17666 Microsoft Site Server formslogin.asp url Parameter XSS Source: BID Type: Exploit, Vendor Advisory 3999 Source: CCN Type: BID-3999 Microsoft Site Server 3.0 Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN siteserver-asp-xss(8050) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |