First published: Fri Feb 05 2010(Updated: )
Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPlanet Logan Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-1587 is considered high due to its potential for cross-site scripting attacks.
To fix CVE-2003-1587, ensure that input validation is applied to User-Agent HTTP headers to prevent script injection.
Users of iPlanet Logan Pro are affected by CVE-2003-1587, particularly those with configurations that allow unfiltered User-Agent headers.
CVE-2003-1587 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
CVE-2003-1587 was disclosed in 2003, highlighting vulnerabilities in the LoganPro software.