CVE-2002-1060
Blue Coat CacheOS - Cross-Site Scripting via Nonexistent Hostname Error Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1060. PoCs published by T.Suzuki.
AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in CacheOS firmware where user-supplied data is not sanitized before being included in an unresolved host error page. An attacker can craft a malicious link with embedded JavaScript that executes in the context of the requested domain.
Description
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.
Exploits (1)
The exploit describes a cross-site scripting (XSS) vulnerability in CacheOS firmware where user-supplied data is not sanitized before being included in an unresolved host error page. An attacker can craft a malicious link with embedded JavaScript that executes in the context of the requested domain.