Back
CVE-2002-1168
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.
Published: Nov 4, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_caching_proxy_server | 3.6 |
| ibm | websphere_caching_proxy_server | 4.0 |
GitHub Security Advisory GHSA-8f3x-2hfc-r4x5
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and...
References (4)
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
1.64%
Top 26% most likely to be exploited
Threat Score
27.7 / 100
Data Sources
NVD
EPSS
GitHub