CVE-2001-0987 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.2% (pctl 94)
Patch early
A public exploit exists.
Description
Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.18% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-07-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| nathan neulinger | cgiwrap |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CGIWrap 2.x/3.x - Cross-Site Scripting | 2001-07-22 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0499.html
- http://cgiwrap.sourceforge.net/changes.html
- http://www.osvdb.org/1909
- http://www.securityfocus.com/bid/3084
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6886
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0499.html
- http://cgiwrap.sourceforge.net/changes.html
- http://www.osvdb.org/1909
- http://www.securityfocus.com/bid/3084
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6886
→ the Explorer · watch your stack · NVD