VulnerabilityModified
CVE-2002-1708
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.
MEDIUM 6.8EPSS 4.26%
Does this matter?
Lower severity and a low EPSS score (4.26%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.26% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- basilix/basilix webmail
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0117.html
- http://online.securityfocus.com/archive/1/277710
- http://www.securityfocus.com/bid/5060Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9384
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0117.html
- http://online.securityfocus.com/archive/1/277710
- http://www.securityfocus.com/bid/5060Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9384
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.