CVE-2002-0771: Medium severity ViewCVS ViewCVS vulnerability
Published Jul 26, 2002
·Updated
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.
Affected Software
4 affected components
ViewCVS ViewCVS=0.9.1
ViewCVS ViewCVS=0.8
ViewCVS ViewCVS=0.9.2
ViewCVS ViewCVS=0.9
Remediation
Patch Available
Patch Available
Event History
Jul 26, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0771?
CVE-2002-0771 has a medium severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-0771?
To fix CVE-2002-0771, upgrade ViewCVS to version 0.9.3 or later where this vulnerability is addressed.
3
Which versions of ViewCVS are affected by CVE-2002-0771?
CVE-2002-0771 affects ViewCVS versions 0.8, 0.9.1, and 0.9.2.
4
What type of vulnerability is CVE-2002-0771?
CVE-2002-0771 is a cross-site scripting vulnerability that allows attackers to inject malicious scripts.
5
Can CVE-2002-0771 lead to cookie theft?
Yes, CVE-2002-0771 can result in cookie theft due to the script injection capability.