Back

CVE-2002-1008

Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

Published: Oct 4, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
summit_computer_networks lil_http_server 2.1
summit_computer_networks lil_http_server 2.2

GitHub Security Advisory GHSA-ph29-776v-p2w9

Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 7.10%

Top 6% most likely to be exploited

Threat Score 32.1 / 100

Data Sources

NVD EPSS GitHub