VYPR
Unrated severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026

CVE-2002-1008

CVE-2002-1008

Description

Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

Affected products

2
  • cpe:2.3:a:summit_computer_networks:lil_http_server:2.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:summit_computer_networks:lil_http_server:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:summit_computer_networks:lil_http_server:2.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.