peter bassill · operator
$ cve CVE-2003-0154 JSON

CVE-2003-0154 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.59% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-02
Last modified2026-06-16

Affected (1)

VendorProduct
mozillabonsai

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD