CVE-2001-0828: Medium severity caucho technology resin vulnerability
Published Dec 6, 2001
·Updated
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.
Affected Software
2 affected components
Caucho Technology Resin<=1.2.4
Caucho Technology Resin=1.2.2
Remediation
Patch Available
Event History
Dec 6, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0828?
CVE-2001-0828 is considered a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2001-0828?
To fix CVE-2001-0828, upgrade to Resin version 1.2.5 or newer.
3
Who is affected by CVE-2001-0828?
CVE-2001-0828 affects all versions of Caucho Technology Resin prior to 1.2.5.
4
What types of attacks can be executed due to CVE-2001-0828?
An attacker can execute malicious JavaScript injections through specially crafted hyperlinks that end in a .jsp extension.
5
What are the potential consequences of CVE-2001-0828 exploitation?
Exploitation of CVE-2001-0828 can lead to unauthorized access to user sessions and sensitive information.