VulnerabilityModified
CVE-2002-1785
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.
LOW 1.9EPSS 2.82%
Does this matter?
Lower severity and a low EPSS score (2.82%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.
- CVSS 2.0
- 1.9 LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.82% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- zeus technologies/zeus web server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0104.htmlExploit, Vendor Advisory
- http://online.securityfocus.com/archive/1/302961Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/10567.php
- http://www.securityfocus.com/bid/6144Exploit, Patch
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0104.htmlExploit, Vendor Advisory
- http://online.securityfocus.com/archive/1/302961Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/10567.php
- http://www.securityfocus.com/bid/6144Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.