Tag Archives: CVE-2002-0980

CWE-344 – Use of Invariant Value in Dynamically Changing Context

Read Time:22 Second

Description

The product uses a constant value, name, or reference, but this value can (or should) vary across different environments.

Modes of Introduction:

– Architecture and Design

 

 

Related Weaknesses

CWE-330

 

Consequences

Other: Varies by Context

 

Potential Mitigations

CVE References

  • CVE-2002-0980
    • Component for web browser writes an error message to a known location, which can then be referenced by attackers to process HTML/script in a less restrictive context