Lucene search

K
cveMitreCVE-2002-0326
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2002-0326

2002-06-2504:00:00
mitre
web.nvd.nist.gov
37
cve-2002-0326
cross-site scripting
badblue
remote attack
javascript

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.006

Percentile

78.8%

Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.

Affected configurations

Nvd
Node
working_resources_inc.badblueMatch1.2.7
OR
working_resources_inc.badblueMatch1.2.8
OR
working_resources_inc.badblueMatch1.5
OR
working_resources_inc.badblueMatch1.5.6_beta
OR
working_resources_inc.badblueMatch1.6.1_beta
VendorProductVersionCPE
working_resources_inc.badblue1.2.7cpe:2.3:a:working_resources_inc.:badblue:1.2.7:*:*:*:*:*:*:*
working_resources_inc.badblue1.2.8cpe:2.3:a:working_resources_inc.:badblue:1.2.8:*:*:*:*:*:*:*
working_resources_inc.badblue1.5cpe:2.3:a:working_resources_inc.:badblue:1.5:*:*:*:*:*:*:*
working_resources_inc.badblue1.5.6_betacpe:2.3:a:working_resources_inc.:badblue:1.5.6_beta:*:*:*:*:*:*:*
working_resources_inc.badblue1.6.1_betacpe:2.3:a:working_resources_inc.:badblue:1.6.1_beta:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.006

Percentile

78.8%

Related for CVE-2002-0326