peter bassill · operator
$ cve CVE-2001-0987 JSON

CVE-2001-0987 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.18% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2001-07-22
Last modified2026-06-16

Affected (1)

VendorProduct
nathan neulingercgiwrap

Public exploits

SourceTitleDate
exploit-dbCGIWrap 2.x/3.x - Cross-Site Scripting2001-07-22

References

→ the Explorer  ·  watch your stack  ·  NVD