CVE-2002-2318 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.45% — more likely to be exploited than 73% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| blueface | falcon web server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BlueFace Falcon Web Server 2.0 - Error Message Cross-Site Scripting | 2002-08-09 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-August/000934.html
- http://seclists.org/lists/bugtraq/2002/Aug/0158.html
- http://www.iss.net/security_center/static/9812.php
- http://www.securityfocus.com/bid/5435
- http://lists.grok.org.uk/pipermail/full-disclosure/2002-August/000934.html
- http://seclists.org/lists/bugtraq/2002/Aug/0158.html
- http://www.iss.net/security_center/static/9812.php
- http://www.securityfocus.com/bid/5435
→ the Explorer · watch your stack · NVD