PT-2009-1145 · Sun · Sunone/Iplanet Web Server
CVE-2004-2763
·
Publicado
2009-06-01
·
Atualizado
2026-05-28
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun ONE/iPlanet Web Server versions 4.1 SP1 through 4.1 SP12
Sun ONE/iPlanet Web Server versions 6.0 SP1 through 6.0 SP5
Description
The default configuration of the web server responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Recommendations
For Sun ONE/iPlanet Web Server versions 4.1 SP1 through 4.1 SP12, disable the HTTP TRACE request to prevent cross-site tracing attacks.
For Sun ONE/iPlanet Web Server versions 6.0 SP1 through 6.0 SP5, disable the HTTP TRACE request to prevent cross-site tracing attacks.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sunone/Iplanet Web Server