Lucene search

K
cveMitreCVE-2003-0154
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2003-0154

2003-04-0205:00:00
mitre
web.nvd.nist.gov
36
cve-2003-0154
cross-site scripting
xss
bonsai
mozilla
cvs query tool
remote attackers
arbitrary web script
cvslog
cvsblame
cvsquery
showcheckins
cvsqueryform
nvd
mozilla bug #146244

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.009

Percentile

83.1%

Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.

Affected configurations

Nvd
Node
mozillabonsaiMatch1.3
VendorProductVersionCPE
mozillabonsai1.3cpe:2.3:a:mozilla:bonsai:1.3:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.009

Percentile

83.1%