Lucene search

K
nvd[email protected]NVD:CVE-2002-1700
HistoryDec 31, 2002 - 5:00 a.m.

CVE-2002-1700

2002-12-3105:00:00
CWE-79
web.nvd.nist.gov
6

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.016

Percentile

87.2%

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Affected configurations

Nvd
Node
macromediacoldfusionMatch6.0
OR
microsoftinternet_information_servicesMatch5.0
Node
microsoftwindows_2000
VendorProductVersionCPE
macromediacoldfusion6.0cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*
microsoftinternet_information_services5.0cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*
microsoftwindows_2000*cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.016

Percentile

87.2%

Related for NVD:CVE-2002-1700