CVE-2002-1685 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)
Patch early
A public exploit exists.
Description
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 7.29% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| working resources inc. | badblue |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Working Resources BadBlue 1.7 - 'ext.dll' Cross-Site Scripting | 2002-06-23 |
References
→ the Explorer · watch your stack · NVD