CVE-2002-1785
Summary
| CVE | CVE-2002-1785 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi. |
Risk And Classification
Primary CVSS: v2.0 1.9 from [email protected]
AV:L/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zeus Technologies | Zeus Web Server | 4.0 | All | All | All |
| Application | Zeus Technologies | Zeus Web Server | 4.1 | All | All | All |
| Application | Zeus Technologies | Zeus Web Server | 4.1_r1 | All | All | All |
| Application | Zeus Technologies | Zeus Web Server | 4.1_r2 | All | All | All |
| Application | Zeus Technologies | Zeus Web Server | 4.1_r3 | All | All | All |
| Application | Zeus Technologies | Zeus Web Server | 4.1_r4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| online.securityfocus.com/archive/1/302961 | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Exploit, Vendor Advisory |
| Neohapsis Archives - Bugtraq - Zeus Admin Server v4.1r2 index.fcgi XSS bug - From just-a-user_at_yandex.ru | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Vendor Advisory |
| Zeus Web Server Admin Interface Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| ISS X-Force Database: zeus-admin-index-xss (10567): Zeus Admin Server index.fcgi script cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.