Back

CVE-2001-1352

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

Published: Dec 27, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
namazu namazu *

GitHub Security Advisory GHSA-6vp8-72hx-47vm

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.58%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub