CVE-2002-1494

Aestiva HTML/OS - Cross-Site Scripting via Trailing Slash Error Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1494. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Aestiva HTML/OS due to insufficient sanitization of metacharacters in error messages. Attackers can inject arbitrary HTML and script code via crafted URLs, which execute in the context of the victim's browser.

Description

Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappscgi
https://www.exploit-db.com/exploits/21769

This exploit demonstrates a reflected XSS vulnerability in Aestiva HTML/OS due to insufficient sanitization of metacharacters in error messages. Attackers can inject arbitrary HTML and script code via crafted URLs, which execute in the context of the victim's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Aestiva HTML/OS
No auth needed
Prerequisites: Access to a vulnerable Aestiva HTML/OS instance · Victim interaction to click a malicious link
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5618
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-09/0026.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10029.php

Scores

EPSS 0.0354
EPSS Percentile 88.1%

Details

Status published
Products (1)
aestiva/html_os 2.4
Published Apr 02, 2003
Tracked Since Feb 18, 2026