First published: Sat Aug 31 2002(Updated: )
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Sitespring | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1027 is classified as a cross-site scripting vulnerability which can allow attackers to execute arbitrary web scripts.
To fix CVE-2002-1027, update to a version of Macromedia Sitespring that does not include the vulnerable 500error.jsp error script.
CVE-2002-1027 specifically affects Macromedia Sitespring version 1.2.0.
Yes, CVE-2002-1027 can be exploited remotely through crafted links to the vulnerable 500error.jsp script.
An attacker can inject and execute arbitrary web scripts in the context of an affected user's session due to CVE-2002-1027.