CVE

Id
9870  
CVE No.
CVE-2004-1442  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error emssages such as "DTWP001E."  
Phase
Assigned (20050213)  
Votes
None (candidate not yet proposed)  
Comments