CVE
- Id
- 5332
- CVE No.
- CVE-2002-0944
- Status
- Candidate
- Description
- Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.
- Phase
- Modified (20030325-01)
- Votes
- ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall
- Comments
- Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed.