Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/636431 | Patch US Government Resource |
http://www.securityfocus.com/bid/5102 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9441 |
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2002-1651
Mitre link : CVE-2002-1651
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
verity
- search97