CVE-2003-1587: XSS
Published Feb 5, 2010
·Updated
Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
Affected Software
1 affected component
iPlanet Loganpro
Event History
Feb 5, 2010
CVE Published
10:30 PM
Data Sourced
via NVD·10:30 PM
DescriptionSeverityWeaknessAffected Software
Feb 6, 2010
CVE Published
via MITRE·03:13 AM
Data Sourced
via MITRE·03:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1587?
The severity of CVE-2003-1587 is considered high due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2003-1587?
To fix CVE-2003-1587, ensure that input validation is applied to User-Agent HTTP headers to prevent script injection.
3
Who is affected by CVE-2003-1587?
Users of iPlanet Logan Pro are affected by CVE-2003-1587, particularly those with configurations that allow unfiltered User-Agent headers.
4
What types of attacks can exploit CVE-2003-1587?
CVE-2003-1587 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
5
When was CVE-2003-1587 disclosed?
CVE-2003-1587 was disclosed in 2003, highlighting vulnerabilities in the LoganPro software.