First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCipher | =0.9.1 | |
nCipher | =0.9.2 | |
nCipher | =0.9.4 | |
nCipher | =0.9 | |
nCipher | =0.9.3 | |
nCipher | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2343 has a moderate severity rating due to its potential to allow remote attackers to execute scripts in the context of a user’s session.
To fix CVE-2002-2343, upgrade NOCC to version 0.9.6 or later where the vulnerability has been addressed.
CVE-2002-2343 affects all versions of NOCC from 0.9 through 0.9.5.
CVE-2002-2343 can enable cross-site scripting (XSS) attacks which could be used to steal session cookies or perform actions on behalf of an unsuspecting user.
A temporary workaround for CVE-2002-2343 is to ensure sanitization of email content to prevent script injection, but upgrading to a patched version is recommended.