PT-2003-1604 · Sun · Sun Java System Web Server+1
Publicado
2003-06-11
·
Atualizado
2016-10-18
·
CVE-2003-0413
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Sun ONE Application Server version 7.0
Sun Java System Web Server version 6.1
Description:
A cross-site scripting (XSS) issue exists in the webapps-simple sample application, allowing remote attackers to insert arbitrary web script or HTML via a crafted HTTP request. This request generates an "Invalid JSP file" error, which in turn inserts the attacker's text into the resulting error message.
Recommendations:
For Sun ONE Application Server version 7.0, update the webapps-simple sample application to prevent the insertion of arbitrary web script or HTML.
For Sun Java System Web Server version 6.1, modify the error handling mechanism to prevent the reflection of user-inputted data in error messages.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sun Java System Web Server
Sun One Application Server