peter bassill · operator
$ cve CVE-2002-1700 JSON

CVE-2002-1700 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 24.3% (pctl 98)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS24.27% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (3)

VendorProduct
macromediacoldfusion
microsoftinternet information services
microsoftwindows 2000

Public exploits

SourceTitleDate
exploit-dbColdFusion MX - Missing Template Cross-Site Scripting2002-06-13

References

→ the Explorer  ·  watch your stack  ·  NVD