Описание
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.
Ссылки
- Vendor Advisory
- Patch
- Patch
- Patch
- Vendor Advisory
- Patch
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:x86:*:*:*:*:*
EPSS
Процентиль: 67%
0.00529
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.
EPSS
Процентиль: 67%
0.00529
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79