CVE-2003-5001
Estado: ModificadaCrítica (9.8)—
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.05%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-269
- NVD-CWE-noinfo
Referencias
- http://www.cgisecurity.com/articles/xss-faq.shtml
- http://www.computec.ch/mruef/advisories/black_ice_pc_protection_xss_evasion.txt
- https://vuldb.com/?id.104
- http://www.cgisecurity.com/articles/xss-faq.shtml
- http://www.computec.ch/mruef/advisories/black_ice_pc_protection_xss_evasion.txt
- https://vuldb.com/?id.104
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-5001",
"cveTags": [
{
"tags": [
"unsupported-when-assigned"
],
"sourceIdentifier": "psirt@us.ibm.com"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "ISS",
"product": "BlackICE PC Protection",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-03-28T21:15:07.863",
"references": [
{
"url": "http://www.cgisecurity.com/articles/xss-faq.shtml",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.computec.ch/mruef/advisories/black_ice_pc_protection_xss_evasion.txt",
"source": "psirt@us.ibm.com"
},
{
"url": "https://vuldb.com/?id.104",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.cgisecurity.com/articles/xss-faq.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.computec.ch/mruef/advisories/black_ice_pc_protection_xss_evasion.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?id.104",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer"
},
{
"lang": "es",
"value": "** NO SOPORTADO CUANDO DE ASIGNÓ ** Se ha encontrado una vulnerabilidad en ISS BlackICE PC Protection y Ha sido clasificada como crítica. Este problema afecta al componente Cross Site Scripting Detection. La manipulación como parte de la petición POST/PUT/DELETE/OPTIONS conlleva a una escalada de privilegios. El ataque puede ser lanzado remotamente. La explotación ha sido divulgada al público y puede ser usada. Es recomendado actualizar el componente afectado. NOTA: Esta vulnerabilidad sólo afecta a productos que ya no son soportados por el mantenedor"
}
],
"lastModified": "2026-06-16T22:04:44.403",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:iss_blackice_pc_protection:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2FE92ADF-24D4-4B3D-9C9B-2409DD21E3E8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}