cbcvebase.
CVE-2003-0615
published 2003-08-27

CVE-2003-0615: Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action…

PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
4.44%
90.3th percentile
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.

Affected

18 ranges
VendorProductVersion rangeFixed in
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
cgi.pmcgi.pm
debiandebian_linux
debianperl< perl 5.8.0-19 (bookworm)perl 5.8.0-19 (bookworm)
openpkgopenpkg
openpkgopenpkg
openpkgopenpkg
perlperl>= 0 < 5.8.0-195.8.0-19
perlperl>= 0 < 5.8.0-195.8.0-19
perlperl>= 0 < 5.8.0-195.8.0-19
perlperl>= 0 < 5.8.0-195.8.0-19

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.