CVE-2002-1348

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:w3m:w3m:0.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.5:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:w3m:w3m:0.3.2.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2003-02-19 05:00

Updated : 2024-02-04 16:31


NVD link : CVE-2002-1348

Mitre link : CVE-2002-1348

CVE.ORG link : CVE-2002-1348


JSON object : View

Products Affected

w3m

  • w3m