CVE
- Id
- 5839
- CVE No.
- CVE-2002-1455
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
- Phase
- Proposed (20030317)
- Votes
- NOOP(4) Christey, Cole, Cox, Wall
- Comments
- Christey> The redir.exe issue involves XSS, but it also involves newline | injection. Should it be SPLIT from this CAN? | | XF:omnihttpd-test-sample-xss(9961) | URL:http://www.iss.net/security_center/static/9961.php | BID:5568 | URL:http://www.securityfocus.com/bid/5568