AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2002-1168

MEDIUM · CVSS 6.8 EPSS 1.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2002-11-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2002-1168
Severity
MEDIUM
CVSS
6.8
EPSS
1.64%

Original NVD Description

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.