peter bassill · operator
$ cve CVE-2002-1036 JSON

CVE-2002-1036 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.18% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (1)

VendorProduct
zoltan milosevicfluid dynamics search engine

Public exploits

SourceTitleDate
exploit-dbFluid Dynamics Search Engine 2.0 - Cross-Site Scripting2002-07-10

References

→ the Explorer  ·  watch your stack  ·  NVD