PT-2001-2101 · Valicert · Valicert Enterprise Validation Authority

CVE-2001-0948

·

Publicado

2001-12-04

·

Atualizado

2024-02-14

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ValiCert Enterprise Validation Authority (EVA) versions 3.3 through 4.2.1
Description A cross-site scripting issue allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.
Recommendations For versions 3.3 through 4.2.1, consider restricting the ability to include HTML or script in certificate descriptions until a fix is available. As a temporary workaround, avoid viewing certificates that may contain malicious code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0948

Produtos afetados

Valicert Enterprise Validation Authority