PT-2008-3638 · Sap · Sap Internet Transaction Server+1

Publicado

2008-05-09

·

Atualizado

2017-08-08

·

CVE-2008-2123

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Internet Transaction Server (ITS) version 6.20
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This can be achieved through a "<>" sequence in the ~service parameter to wgate.dll, or via Javascript splicing in the query string.
Recommendations For SAP Internet Transaction Server (ITS) version 6.20, consider restricting access to the wgate.dll module to minimize the risk of exploitation. Avoid using the ~service parameter with untrusted input until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2123

Produtos afetados

Sap Internet Transaction Server
Wgate.Dll