Vulnerabilities > CVE-2002-0771 - Unspecified vulnerability in Viewcvs
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | ViewCVS 0.9.2 Cross-Site Scripting Vulnerability. CVE-2002-0771. Webapps exploit for cgi platform |
id | EDB-ID:21473 |
last seen | 2016-02-02 |
modified | 2002-05-24 |
published | 2002-05-24 |
reporter | office |
source | https://www.exploit-db.com/download/21473/ |
title | ViewCVS 0.9.2 - Cross-Site Scripting Vulnerability |
Nessus
NASL family | CGI abuses : XSS |
NASL id | VIEWCVS_XSS.NASL |
description | The remote host is running ViewCVS, a tool written in Python to browse CVS repositories via the web. The version of ViewCVS running on the remote host has a cross-site scripting vulnerability. Input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14823 |
published | 2004-09-27 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14823 |
title | ViewCVS viewcvs.cgi Multiple Parameter XSS |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0161.html
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0161.html
- http://www.iss.net/security_center/static/9112.php
- http://www.iss.net/security_center/static/9112.php
- http://www.securityfocus.com/bid/4818
- http://www.securityfocus.com/bid/4818