First published: Wed Dec 31 2003(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | =2.1.2 | |
Caucho Resin | =2.1.1 | |
Caucho Resin | =2.0 | |
Caucho Resin | =2.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1513 is classified as a medium severity vulnerability due to potential exploitation via cross-site scripting attacks.
To fix CVE-2003-1513, upgrade to a later version of Caucho Resin that addresses these XSS issues.
CVE-2003-1513 affects Caucho Resin versions 2.0, 2.1.1, 2.1.2, and 2.1.12.
CVE-2003-1513 can be exploited through cross-site scripting (XSS) to inject arbitrary web scripts or HTML.
While CVE-2003-1513 was reported in 2003, it is crucial to ensure that any legacy systems using the affected versions are updated to prevent potential exploitation.