Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/636431 | Patch US Government Resource |
http://www.securityfocus.com/bid/5102 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9441 | |
http://www.kb.cert.org/vuls/id/636431 | Patch US Government Resource |
http://www.securityfocus.com/bid/5102 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9441 |
Configurations
History
20 Nov 2024, 23:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/636431 - Patch, US Government Resource | |
References | () http://www.securityfocus.com/bid/5102 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/9441 - |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:41
NVD link : CVE-2002-1651
Mitre link : CVE-2002-1651
CVE.ORG link : CVE-2002-1651
JSON object : View
Products Affected
verity
- search97
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')