CVE-2002-1494
Aestiva HTML/OS - Cross-Site Scripting via Trailing Slash Error Message
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1494. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Aestiva HTML/OS due to insufficient sanitization of metacharacters in error messages. Attackers can inject arbitrary HTML and script code via crafted URLs, which execute in the context of the victim's browser.
Description
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Aestiva HTML/OS due to insufficient sanitization of metacharacters in error messages. Attackers can inject arbitrary HTML and script code via crafted URLs, which execute in the context of the victim's browser.