CVE-2002-1335: XSS
Published Dec 3, 2002
·Updated
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.
Affected Software
1 affected component
w3m w3m=0.3.2
Remediation
Patch Available
Patch Available
Event History
Dec 3, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1335?
CVE-2002-1335 has a medium severity rating due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2002-1335?
To fix CVE-2002-1335, update w3m to a version that addresses the XSS vulnerability.
3
What does CVE-2002-1335 exploit?
CVE-2002-1335 exploits a lack of HTML tag escaping in w3m, enabling attackers to inject arbitrary scripts.
4
Who is affected by CVE-2002-1335?
Users of w3m version 0.3.2 are affected by CVE-2002-1335.
5
How can CVE-2002-1335 impact a user?
CVE-2002-1335 can lead to unauthorized access to cookies and sensitive data by executing malicious scripts in the user's browser.