CVE-2002-0166

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:stephen_turner:analog:3.90_beta1:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:3.90_beta2:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.1:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.01:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.02:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.03:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.04:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.11:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.14:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.15:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.16:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.90_beta2:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.90_beta3:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.90_beta4:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:4.91_beta1:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.0:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.01:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.1a:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.2:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.02:*:*:*:*:*:*:*
cpe:2.3:a:stephen_turner:analog:5.03:*:*:*:*:*:*:*

History

No history.

Information

Published : 2002-04-22 04:00

Updated : 2024-02-04 16:31


NVD link : CVE-2002-0166

Mitre link : CVE-2002-0166

CVE.ORG link : CVE-2002-0166


JSON object : View

Products Affected

stephen_turner

  • analog