CVE-2002-1348

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:w3m:w3m:0.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.5:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=104552193927323&w=2 - () http://marc.info/?l=bugtraq&m=104552193927323&w=2 -
References () http://sourceforge.net/project/shownotes.php?release_id=126233 - Vendor Advisory () http://sourceforge.net/project/shownotes.php?release_id=126233 - Vendor Advisory
References () http://www.debian.org/security/2003/dsa-249 - () http://www.debian.org/security/2003/dsa-249 -
References () http://www.debian.org/security/2003/dsa-250 - () http://www.debian.org/security/2003/dsa-250 -
References () http://www.debian.org/security/2003/dsa-251 - () http://www.debian.org/security/2003/dsa-251 -
References () http://www.iss.net/security_center/static/11266.php - Patch, Vendor Advisory () http://www.iss.net/security_center/static/11266.php - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2003-044.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2003-044.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2003-045.html - () http://www.redhat.com/support/errata/RHSA-2003-045.html -
References () http://www.securityfocus.com/bid/6794 - () http://www.securityfocus.com/bid/6794 -

Information

Published : 2003-02-19 05:00

Updated : 2024-11-20 23:41


NVD link : CVE-2002-1348

Mitre link : CVE-2002-1348

CVE.ORG link : CVE-2002-1348


JSON object : View

Products Affected

w3m

  • w3m