CVE-2002-2246: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTPREFERER) to a non-existent page, which is injected into the resulting 404 error page.
Affected Software
1 affected component
Deerfield VisNetic WebSite<=3.5.13
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 15, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2246?
CVE-2002-2246 is classified as a medium severity vulnerability that allows cross-site scripting attacks.
2
How do I fix CVE-2002-2246?
To fix CVE-2002-2246, upgrade VisNetic Website to version 3.5.15 or later.
3
What is the impact of CVE-2002-2246?
The impact of CVE-2002-2246 allows attackers to inject arbitrary web scripts into the 404 error pages.
4
Which versions of VisNetic Website are affected by CVE-2002-2246?
CVE-2002-2246 affects all versions of VisNetic Website prior to 3.5.15.
5
Who is affected by CVE-2002-2246?
Any users or organizations running VisNetic Website versions up to 3.5.13 are affected by CVE-2002-2246.