Vulnerabilities > CVE-2002-1494 - Cross-Site Scripting vulnerability in Aestiva Html OS 2.4

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
aestiva
exploit available

Summary

Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.

Vulnerable Configurations

Part Description Count
Application
Aestiva
1

Exploit-Db

descriptionAestiva HTML/OS 2.4 Cross-Site Scripting Vulnerability. CVE-2002-1494. Webapps exploit for cgi platform
idEDB-ID:21769
last seen2016-02-02
modified2002-09-03
published2002-09-03
reporter[email protected]
sourcehttps://www.exploit-db.com/download/21769/
titleAestiva HTML/OS 2.4 - Cross-Site Scripting Vulnerability