Verity Search97 XSS Vulnerability: Remote Code Injection and Information Theft

Verity Search97 XSS Vulnerability: Remote Code Injection and Information Theft

CVE-2002-1651 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.

Learn more about our Web App Pen Testing.