Sploitus

CVE-2004-2171

1 known exploit for CVE-2004-2171

Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.

Affected products
Cherokee
Cherokee Cherokee Httpd
= 0.1, 0.1.5, 0.1.6, 0.2, 0.2.5, 0.2.6, 0.2.7, 0.4.6, 0.4.7
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
3.6% (89th percentile)
NVD status
Modified
Published
2005-07-10
CVE-2004-2171 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2004-2171

Proof-of-concept code and exploit modules indexed by Sploitus