Vulnerabilities > CVE-2002-1965 - Cross-Site Scripting vulnerability in Imatix Xitami 2.5B4/2.5B5

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
imatix
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request.

Vulnerable Configurations

Part Description Count
Application
Imatix
2

Exploit-Db

descriptionImatix Xitami 2.5 GSL Template Cross Site Scripting Vulnerability. CVE-2002-1965. Remote exploit for windows platform
idEDB-ID:21554
last seen2016-02-02
modified2002-06-14
published2002-06-14
reporterMatthew Murphy
sourcehttps://www.exploit-db.com/download/21554/
titleImatix Xitami 2.5 GSL Template Cross-Site Scripting Vulnerability