Unrated severityNVD Advisory· Published Dec 6, 2001· Updated Apr 16, 2026
CVE-2001-0828
CVE-2001-0828
Description
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.
Affected products
2cpe:2.3:a:caucho_technology:resin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:caucho_technology:resin:*:*:*:*:*:*:*:*range: <=1.2.4
- cpe:2.3:a:caucho_technology:resin:1.2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/2981nvdExploitPatchVendor Advisory
- www.caucho.com/products/resin/changes.xtpnvdVendor Advisory
- www.kb.cert.org/vuls/id/981651nvdUS Government Resource
- archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.htmlnvd
- www.osvdb.org/1890nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/6793nvd
News mentions
0No linked articles in our index yet.