CVE-2003-1543
Summary
| CVE | CVE-2003-1543 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bajie | Java Http Server | 0.95 | zxc | All | All |
| Application | Bajie | Java Http Server | 0.95 | zxe | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BajieServer security page | af854a3a-2127-422b-91ae-364da2661108 | www.geocities.com | |
| Secunia - Advisories - Bajie Web Server Cross Site Scripting | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Luca Ercoli - IT Security Specialist | af854a3a-2127-422b-91ae-364da2661108 | www.lucaercoli.it | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bajie Error Message Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| BajieServer Input Validation Hole Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| 'Bajie HTTP Server Cross-Site Scripting Vulnerability' - SecuriTeam | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.