Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2003-0154
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 6.8/10
- Exploit Score
- 8.6/10
- Access Vector
- Network
- Access Complexity
- Medium
- Authentication Required
- None
- Impact Score
- 6.4/10
- Confidentiality Impact
- Partial
- Availability Impact
- Partial
- Integrity Impact
- Partial
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:mozilla:bonsai:1.3:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://www.debian.org/security/2003/dsa-265
- http://www.securityfocus.com/bid/5516
- http://bugzilla.mozilla.org/show_bug.cgi?id=163573
- http://bugzilla.mozilla.org/show_bug.cgi?id=146244
- http://www.iss.net/security_center/static/9920.php
- http://bugzilla.mozilla.org/attachment.cgi?id=95950&action=view
- http://bugzilla.mozilla.org/attachment.cgi?id=95985&action=view
- http://marc.info/?l=bugtraq&m=102980129101054&w=2