CVE-2002-0733: High severity Acme Labs thttpd vulnerability
Published Aug 12, 2002
·Updated
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
Affected Software
1 affected component
Acme Labs thttpd=2.20b
Event History
Aug 12, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0733?
CVE-2002-0733 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-0733?
To fix CVE-2002-0733, upgrade thttpd to version 2.21 or later where the vulnerability is addressed.
3
What type of attacks can CVE-2002-0733 lead to?
CVE-2002-0733 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in a user's browser.
4
What versions of thttpd are affected by CVE-2002-0733?
CVE-2002-0733 affects thttpd versions 2.20 and earlier.
5
Can CVE-2002-0733 be exploited by remote attackers?
Yes, CVE-2002-0733 can be exploited by remote attackers through specially crafted URLs to nonexistent pages.