Vulnerability Description
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Application Server | 3.0.2 |
References
- http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html
- http://www.securityfocus.com/bid/2969ExploitPatchVendor Advisory
- http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html
- http://www.securityfocus.com/bid/2969ExploitPatchVendor Advisory
FAQ
What is CVE-2001-0824?
CVE-2001-0824 is a vulnerability with a CVSS score of 7.5 (HIGH). Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to t...
How severe is CVE-2001-0824?
CVE-2001-0824 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0824?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Application Server.