CVE-2002-2318

Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blueface:falcon_web_server:2.0.0.1009:*:*:*:*:*:*:*
cpe:2.3:a:blueface:falcon_web_server:2.0.0.1020:*:*:*:*:*:*:*
cpe:2.3:a:blueface:falcon_web_server:2.0.0.1021:*:*:*:*:*:*:*
cpe:2.3:a:blueface:falcon_web_server:2.0.0.1021_ssl:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2002-August/000934.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2002-August/000934.html -
References () http://seclists.org/lists/bugtraq/2002/Aug/0158.html - Exploit () http://seclists.org/lists/bugtraq/2002/Aug/0158.html - Exploit
References () http://www.iss.net/security_center/static/9812.php - () http://www.iss.net/security_center/static/9812.php -
References () http://www.securityfocus.com/bid/5435 - Exploit () http://www.securityfocus.com/bid/5435 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:43


NVD link : CVE-2002-2318

Mitre link : CVE-2002-2318

CVE.ORG link : CVE-2002-2318


JSON object : View

Products Affected

blueface

  • falcon_web_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')