Vulnerabilities > CVE-2002-1168 - Unspecified vulnerability in IBM Websphere Caching Proxy Server 3.6/4.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ibm
exploit available

Summary

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

Vulnerable Configurations

Part Description Count
Application
Ibm
2

Exploit-Db

descriptionIBM Websphere Edge Server 3.69/4.0 HTTP Header Injection Vulnerability. CVE-2002-1168 . Remote exploit for unix platform
idEDB-ID:21948
last seen2016-02-02
modified2002-10-23
published2002-10-23
reporterRapid7
sourcehttps://www.exploit-db.com/download/21948/
titleIBM Websphere Edge Server 3.69/4.0 HTTP Header Injection Vulnerability