Back
CVE-2001-0948
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.
Published: Dec 4, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| valicert | enterprise_validation_authority | 3.3 |
| valicert | enterprise_validation_authority | 3.4 |
| valicert | enterprise_validation_authority | 3.5 |
| valicert | enterprise_validation_authority | 3.6 |
| valicert | enterprise_validation_authority | 3.7 |
| valicert | enterprise_validation_authority | 3.8 |
| valicert | enterprise_validation_authority | 3.9 |
| valicert | enterprise_validation_authority | 4.0 |
| valicert | enterprise_validation_authority | 4.1 |
| valicert | enterprise_validation_authority | 4.2 |
| valicert | enterprise_validation_authority | 4.2.1 |
GitHub Security Advisory GHSA-cwm8-32rv-7w26
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3...
References (8)
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.securityfocus.com/bid/3619 Patch, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.html Vendor Advisory, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7650
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.securityfocus.com/bid/3619 Patch, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.html Vendor Advisory, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7650
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.29%
Top 18% most likely to be exploited
Threat Score
30.7 / 100
Data Sources
NVD
EPSS
GitHub