CVE-2001-0824

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_application_server:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:3.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:36

Type Values Removed Values Added
References () http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html - () http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html -
References () http://www.securityfocus.com/bid/2969 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/bid/2969 - Exploit, Patch, Vendor Advisory

Information

Published : 2001-12-06 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2001-0824

Mitre link : CVE-2001-0824

CVE.ORG link : CVE-2001-0824


JSON object : View

Products Affected

ibm

  • websphere_application_server