Vulnerabilities > CVE-2001-1202 - Cross-Site Scripting vulnerability in DeleGate

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
delegate
exploit available

Summary

Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

Vulnerable Configurations

Part Description Count
Application
Delegate
4

Exploit-Db

descriptionDeleGate 7.7.1 Cross-Site Scripting Vulnerability. CVE-2001-1202. Remote exploits for multiple platform
idEDB-ID:21193
last seen2016-02-02
modified2001-12-28
published2001-12-28
reporterSNS Research
sourcehttps://www.exploit-db.com/download/21193/
titleDeleGate 7.7.1 - Cross-Site Scripting Vulnerability