VDB
CVE-2002-1348
CVE-2002-1348
PUBLISHED
CVSS 5 MEDIUM
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
EPSS 2.03% · 79.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.03%
79.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| w3m | w3m | 0.2, 0.2.1, 0.2.2 |
Timeline
- Feb 19, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Apr 30, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- DSA-250 vendor-advisory
- 20030217 GLSA: w3m mailing-list
- http://sourceforge.net/project/shownotes.php?release_id=126233 url
- http://www.debian.org/security/2003/dsa-251 technical
- http://www.redhat.com/support/errata/RHSA-2003-045.html technical
- http://www.securityfocus.com/bid/6794 technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-1348 advisory
- http://www.debian.org/security/2003/dsa-249 url
- http://www.iss.net/security_center/static/11266.php url
- http://www.redhat.com/support/errata/RHSA-2003-044.html url