Back

CVE-2002-0166

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.

Published: Apr 22, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (21)

Vendor Product Version
stephen_turner analog 3.90_beta1
stephen_turner analog 3.90_beta2
stephen_turner analog 4.1
stephen_turner analog 4.01
stephen_turner analog 4.02
stephen_turner analog 4.03
stephen_turner analog 4.04
stephen_turner analog 4.11
stephen_turner analog 4.14
stephen_turner analog 4.15
stephen_turner analog 4.16
stephen_turner analog 4.90_beta2
stephen_turner analog 4.90_beta3
stephen_turner analog 4.90_beta4
stephen_turner analog 4.91_beta1
stephen_turner analog 5.0
stephen_turner analog 5.01
stephen_turner analog 5.1a
stephen_turner analog 5.2
stephen_turner analog 5.02

…and 1 more

GitHub Security Advisory GHSA-6736-7xch-7c42

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.80%

Top 24% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub