Vulnerabilities > CVE-2002-1027 - Cross-Site Scripting vulnerability in Macromedia Sitespring 1.2.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
macromedia
exploit available

Summary

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.

Vulnerable Configurations

Part Description Count
Application
Macromedia
1

Exploit-Db

descriptionMacromedia Sitespring 1.2 Default Error Page Cross Site Scripting Vulnerability. CVE-2002-1027 . Webapps exploit for jsp platform
idEDB-ID:21621
last seen2016-02-02
modified2002-07-17
published2002-07-17
reporterPeter Gründl
sourcehttps://www.exploit-db.com/download/21621/
titleMacromedia Sitespring 1.2 Default Error Page Cross-Site Scripting Vulnerability