First published: Fri May 03 2002(Updated: )
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Working Resources Inc. BadBlue | =1.6.1_beta | |
Working Resources Inc. BadBlue | =1.5 | |
Working Resources Inc. BadBlue | =1.5.6_beta | |
Working Resources Inc. BadBlue | =1.2.8 | |
Working Resources Inc. BadBlue | =1.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0326 has a medium severity rating due to its potential for remote script execution.
To fix CVE-2002-0326, upgrade BadBlue to version 1.6.1 beta or later.
CVE-2002-0326 affects BadBlue versions 1.5, 1.5.6 beta, 1.2.8, and 1.2.7.
Yes, CVE-2002-0326 can allow attackers to execute arbitrary scripts and potentially additional commands via specially crafted URLs.
CVE-2002-0326 is classified as a cross-site scripting (XSS) vulnerability.