First published: Fri Oct 04 2002(Updated: )
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blue Coat CacheOS | =3.1.17 | |
Blue Coat CacheOS | =3.1.18 | |
Blue Coat CacheOS | =3.1.19 | |
Blue Coat CacheOS | =3.1.21 | |
Blue Coat CacheOS | =4.0 | |
Blue Coat CacheOS | =4.0.11 | |
Blue Coat CacheOS | =4.0.12 | |
Blue Coat CacheOS | =4.0.13 | |
Blue Coat CacheOS | =4.0.14 | |
Blue Coat CacheOS | =4.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1060 is classified as a medium severity vulnerability.
To mitigate CVE-2002-1060, it is recommended to upgrade to a patched version of Blue Coat CacheOS.
CVE-2002-1060 affects Blue Coat CacheOS versions including 3.1.17, 3.1.18, 3.1.19, 3.1.21, 4.0, and 4.1.6.
CVE-2002-1060 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2002-1060 can be exploited by remote attackers.