CVE-2002-1493
Lycos HTMLGear guestbook - Cross-Site Scripting via IMG Tag Attributes
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1493. PoCs published by Matthew Murphy.
AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in Lycos htmlGEAR guestGEAR due to insufficient sanitization of HTML/CSS in guestbook fields. Attackers can inject arbitrary JavaScript via STYLE attributes or IMG tags, executing in the context of the victim's browser.
Description
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.
Exploits (1)
The exploit describes a cross-site scripting (XSS) vulnerability in Lycos htmlGEAR guestGEAR due to insufficient sanitization of HTML/CSS in guestbook fields. Attackers can inject arbitrary JavaScript via STYLE attributes or IMG tags, executing in the context of the victim's browser.