Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2001-0991


Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.


Published

2001-07-24T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application scott_r._lemmon proxomitron_naoko-4 beta1 Yes
Application scott_r._lemmon proxomitron_naoko-4 beta2 Yes
Application scott_r._lemmon proxomitron_naoko-4 beta3 Yes
Application scott_r._lemmon proxomitron_naoko-4 beta4 Yes

References