PT-2001-2101 · Valicert · Valicert Enterprise Validation Authority
CVE-2001-0948
·
Publicado
2001-12-04
·
Atualizado
2024-02-14
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ValiCert Enterprise Validation Authority (EVA) versions 3.3 through 4.2.1
Description
A cross-site scripting issue allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.
Recommendations
For versions 3.3 through 4.2.1, consider restricting the ability to include HTML or script in certificate descriptions until a fix is available. As a temporary workaround, avoid viewing certificates that may contain malicious code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Valicert Enterprise Validation Authority