AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2002-1157

HIGH · CVSS 7.5 EPSS 9.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2002-11-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2002-1157
Severity
HIGH
CVSS
7.5
EPSS
9.70%
Apache

Original NVD Description

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.