CVE-2002-0771

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2002
Last modified:
19/11/2016

Description

Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:viewcvs:viewcvs:0.8:*:*:*:*:*:*:*
cpe:2.3:a:viewcvs:viewcvs:0.9:*:*:*:*:*:*:*
cpe:2.3:a:viewcvs:viewcvs:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:viewcvs:viewcvs:0.9.2:*:*:*:*:*:*:*