VulnerabilityModified
CVE-2002-1348
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
MEDIUM 5.0EPSS 2.03%
Does this matter?
Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.
Description
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- w3m/w3m
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=104552193927323&w=2
- http://sourceforge.net/project/shownotes.php?release_id=126233Vendor Advisory
- http://www.debian.org/security/2003/dsa-249
- http://www.debian.org/security/2003/dsa-250
- http://www.debian.org/security/2003/dsa-251
- http://www.iss.net/security_center/static/11266.phpPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-044.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-045.html
- http://www.securityfocus.com/bid/6794
- http://marc.info/?l=bugtraq&m=104552193927323&w=2
- http://sourceforge.net/project/shownotes.php?release_id=126233Vendor Advisory
- http://www.debian.org/security/2003/dsa-249
- http://www.debian.org/security/2003/dsa-250
- http://www.debian.org/security/2003/dsa-251
- http://www.iss.net/security_center/static/11266.phpPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-044.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-045.html
- http://www.securityfocus.com/bid/6794
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.