Back

CVE-2002-0733

Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
acme_labs thttpd 2.20b

GitHub Security Advisory GHSA-97fv-j39h-gpq7

Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 8.03%

Top 6% most likely to be exploited

Threat Score 32.4 / 100

Data Sources

NVD EPSS GitHub