CVE-2013-4098

DS3 Authentication Server - Improper Input Validation

Title source: rule
STIX 2.1

Description

ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.

Exploits (1)

exploitdb WRITEUP
by Pedro Andujar · textwebappshardware
https://www.exploit-db.com/exploits/25976

References (2)

Core 2

Scores

EPSS 0.0488
EPSS Percentile 89.6%

Details

CWE
CWE-20
Status published
Products (1)
ds3/authentication_server
Published Jun 28, 2013
Tracked Since Feb 18, 2026