CVE Vulnerabilities

CVE-2002-0771

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.

Affected Software

NameVendorStart VersionEnd Version
ViewcvsViewcvs0.8 (including)0.8 (including)
ViewcvsViewcvs0.9 (including)0.9 (including)
ViewcvsViewcvs0.9.1 (including)0.9.1 (including)
ViewcvsViewcvs0.9.2 (including)0.9.2 (including)

References