Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2763

Опубликовано: 01 июн. 2009
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sun:iplanet_web_server:4.1:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp1:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp10:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp10:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp11:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp11:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp12:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp12:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp2:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp3:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp4:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp4:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp5:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp5:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp6:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp6:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp7:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp7:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp8:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp8:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp9:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:4.1:sp9:enterprise:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:6.0:sp4:*:*:*:*:*:*
cpe:2.3:a:sun:iplanet_web_server:6.0:sp5:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp10:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp11:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp12:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp4:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp5:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp6:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp7:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp8:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:4.1:sp9:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:6.0:sp4:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:6.0:sp5:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:6.1:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:one_web_server:6.1:sp2:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.0072
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-16

Связанные уязвимости

github
почти 4 года назад

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

EPSS

Процентиль: 72%
0.0072
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-16