First published: Thu Dec 06 2001(Updated: )
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | <=1.2.4 | |
Caucho Resin | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0828 is considered a moderate severity cross-site scripting vulnerability.
To fix CVE-2001-0828, upgrade to Resin version 1.2.5 or newer.
CVE-2001-0828 affects all versions of Caucho Technology Resin prior to 1.2.5.
An attacker can execute malicious JavaScript injections through specially crafted hyperlinks that end in a .jsp extension.
Exploitation of CVE-2001-0828 can lead to unauthorized access to user sessions and sensitive information.