CVE-2003-1511
Summary
| CVE | CVE-2003-1511 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bajie | Java Http Server | 0.95 | All | All | All |
| Application | Bajie | Java Http Server | 0.95 | d | All | All |
| Application | Bajie | Java Http Server | 0.95 | zxc | All | All |
| Application | Bajie | Java Http Server | 0.95 | zxe | All | All |
| Application | Bajie | Java Http Server | 0.95 | zxe1 | All | All |
| Application | Bajie | Java Http Server | 0.95 | zxv4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BajieServer security page | af854a3a-2127-422b-91ae-364da2661108 | www.geocities.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CSS Vulnerability in Bajie HTTP JServer - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Exploit |
| Bajie HTTP Server Example Scripts And Servlets Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Secunia - Advisories - Bajie Http Web Server Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.