CVE-2002-1060: XSS
Published Oct 4, 2002
·Updated
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.
Affected Software
10 affected components
bluecoat Cacheos=3.1.17
bluecoat Cacheos=3.1.18
bluecoat Cacheos=3.1.19
bluecoat Cacheos=3.1.21
bluecoat Cacheos=4.0
bluecoat Cacheos=4.0.11
bluecoat Cacheos=4.0.12
bluecoat Cacheos=4.0.13
bluecoat Cacheos=4.0.14
bluecoat Cacheos=4.1.6
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1060?
CVE-2002-1060 is classified as a medium severity vulnerability.
2
How do I fix CVE-2002-1060?
To mitigate CVE-2002-1060, it is recommended to upgrade to a patched version of Blue Coat CacheOS.
3
Which versions of Blue Coat CacheOS are affected by CVE-2002-1060?
CVE-2002-1060 affects Blue Coat CacheOS versions including 3.1.17, 3.1.18, 3.1.19, 3.1.21, 4.0, and 4.1.6.
4
What type of vulnerability is CVE-2002-1060?
CVE-2002-1060 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2002-1060 be exploited remotely?
Yes, CVE-2002-1060 can be exploited by remote attackers.