Vulnerability Description
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 4.0.3 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0014.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=102631703811297&w=2
- http://www.osvdb.org/4973
- http://www.securityfocus.com/bid/5193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9520
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bd
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0014.htmlPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=102631703811297&w=2
- http://www.osvdb.org/4973
- http://www.securityfocus.com/bid/5193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9520
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bd
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c
FAQ
What is CVE-2002-0682?
CVE-2002-0682 is a vulnerability with a CVSS score of 7.5 (HIGH). Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script ...
How severe is CVE-2002-0682?
CVE-2002-0682 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0682?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.