CVE-2003-0053

Apple Darwin Streaming Server 4.1.2 & QuickTime Streaming Server 4.1.1 XSS via parse_xml.cgi

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104618904330226&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6958
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11404.php

Scores

EPSS 0.0182
EPSS Percentile 76.5%

Details

Status published
Products (2)
apple/darwin_streaming_server 4.1.2
apple/quicktime_streaming_server 4.1.1
Published Mar 07, 2003
Tracked Since Feb 18, 2026