Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omnicron | Omnihttpd | All versions |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0263.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0264.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0266.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0263.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0264.htmlExploitVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-08/0266.htmlExploitVendor Advisory
FAQ
What is CVE-2002-1455?
CVE-2002-1455 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
How severe is CVE-2002-1455?
CVE-2002-1455 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1455?
Check the references section above for vendor advisories and patch information. Affected products include: Omnicron Omnihttpd.