Cross-Site Scripting Vulnerability in Microsoft Site Server 3.0
CVE-2002-2073

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
31 December 2002

What is CVE-2002-2073?

Microsoft Site Server 3.0 on Windows NT 4.0 is susceptible to a cross-site scripting (XSS) vulnerability caused by improper validation of input on the default ASP pages. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'ctr' parameter in Default.asp and the query string of formslogin.asp. Exploiting this vulnerability can lead to the execution of malicious scripts in a user's browser, potentially compromising sensitive information and session tokens.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.