First published: Mon Aug 12 2002(Updated: )
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acme Labs thttpd | =2.20b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0733 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2002-0733, upgrade thttpd to version 2.21 or later where the vulnerability is addressed.
CVE-2002-0733 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in a user's browser.
CVE-2002-0733 affects thttpd versions 2.20 and earlier.
Yes, CVE-2002-0733 can be exploited by remote attackers through specially crafted URLs to nonexistent pages.