VYPR

Electronic Documentation

Sign in to watch

by Nokia

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2003-08020.030.02Oct 6, 2003Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).
CVE-2003-08010.030.00Oct 6, 2003Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.
CVE-2003-08030.030.02Oct 6, 2003Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.