PT-2003-1604 · Sun · Sun Java System Web Server+1

Publicado

2003-06-11

·

Atualizado

2016-10-18

·

CVE-2003-0413

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Sun ONE Application Server version 7.0 Sun Java System Web Server version 6.1
Description: A cross-site scripting (XSS) issue exists in the webapps-simple sample application, allowing remote attackers to insert arbitrary web script or HTML via a crafted HTTP request. This request generates an "Invalid JSP file" error, which in turn inserts the attacker's text into the resulting error message.
Recommendations: For Sun ONE Application Server version 7.0, update the webapps-simple sample application to prevent the insertion of arbitrary web script or HTML. For Sun Java System Web Server version 6.1, modify the error handling mechanism to prevent the reflection of user-inputted data in error messages.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0413

Produtos afetados

Sun Java System Web Server
Sun One Application Server