First published: Tue Dec 31 2002(Updated: )
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Working Resources Inc. BadBlue | =personal_1.7.2 | |
Working Resources Inc. BadBlue | =enterprise_1.7.2 | |
Working Resources Inc. BadBlue | =personal_1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1685 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2002-1685, upgrade to BadBlue Enterprise Edition or Personal Edition version 1.7.3 or later.
CVE-2002-1685 affects BadBlue versions 1.7 and 1.7.2 for both Enterprise and Personal Editions.
Cross-site scripting in CVE-2002-1685 allows attackers to inject malicious scripts into web pages viewed by other users.
Remote attackers can exploit CVE-2002-1685 to execute arbitrary scripts on behalf of other users.