CVE-2002-2010: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.
Affected Software
4 affected components
htdig htdig=3.1.5
htdig htdig=3.2.0b3
htdig htdig=3.1.6
htdig htdig=3.2.0
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2010?
CVE-2002-2010 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-2010?
To fix CVE-2002-2010, upgrade to updated versions of ht://Dig that address the XSS vulnerability.
3
Which versions are affected by CVE-2002-2010?
CVE-2002-2010 affects ht://Dig versions 3.1.5, 3.1.6, 3.2.0, and 3.2.0b3.
4
What is the impact of CVE-2002-2010?
The impact of CVE-2002-2010 allows remote attackers to inject arbitrary web scripts or HTML into the application.
5
What should I do if I cannot upgrade to fix CVE-2002-2010?
If you cannot upgrade, implement web application firewalls or input validation measures to help mitigate CVE-2002-2010.