CVE Vulnerabilities

CVE-2002-0771

Published: Aug 12, 2002 | Modified: Nov 19, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.

Affected Software

Name Vendor Start Version End Version
Viewcvs Viewcvs 0.8 (including) 0.8 (including)
Viewcvs Viewcvs 0.9 (including) 0.9 (including)
Viewcvs Viewcvs 0.9.1 (including) 0.9.1 (including)
Viewcvs Viewcvs 0.9.2 (including) 0.9.2 (including)

References