CVE-2002-1335Cross-site Scripting in W3M

7 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
1.4%
top 19.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateApr 30

Description

Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiantats/w3m< 0.3.2.2-1+3
NVDw3m/w3m0.3.2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g49v-5ppg-cxcg: Cross-site scripting (XSS) vulnerability in w3m 02022-04-30
OSV
CVE-2002-1335: Cross-site scripting (XSS) vulnerability in w3m 02002-12-11
CVEList
CVE-2002-1335: Cross-site scripting (XSS) vulnerability in w3m 02002-12-03

📋Vendor Advisories

2
Red Hat
security flaw2002-11-27
Debian
CVE-2002-1335: w3m - Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML ta...2002

💬Community

1
Bugzilla
CVE-2002-1335 security flaw2018-08-16