Record summary

CVE-2002-1168 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM Websphere Edge Server 3.69/4.0 - HTTP Header InjectionExploitDB exploitby Rapid7Not analyzed1 file
ExploitDB

PoC details

References

3