Vulnerability Name: | CVE-2003-0413 (CCN-12095) | ||||||||
Assigned: | 2003-05-27 | ||||||||
Published: | 2003-05-27 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue May 27 2003 - 17:48:04 CDT Multiple Vulnerabilities in Sun-One Application Server Source: MITRE Type: CNA CVE-2003-0413 Source: BUGTRAQ Type: UNKNOWN 20030526 Multiple Vulnerabilities in Sun-One Application Server Source: CCN Type: Sun Alert ID: 55221 Sun One Application Server May Disclose JSP Source Source: SUNALERT Type: Patch, Vendor Advisory 55221 Source: SUNALERT Type: UNKNOWN 57605 Source: SUNALERT Type: UNKNOWN 201009 Source: SUNALERT Type: UNKNOWN 1000610 Source: CCN Type: CIAC Information Bulletin N-103 Sun ONE Application Server May Disclose JavaServer Pages (JSP) Source Source: CIAC Type: Patch, Vendor Advisory N-103 Source: XF Type: Patch, Vendor Advisory sunone-http-error-xss(12095) Source: CCN Type: OSVDB ID: 8197 Sun Java System webapps-simple Application XSS Source: CCN Type: OSVDB ID: 9191 Sun ONE Application Server Invalid JSP File Error XSS Source: BID Type: Exploit, Patch, Vendor Advisory 7710 Source: CCN Type: BID-7710 Sun ONE Application Server Error Message Cross-Site Scripting Vulnerability Source: MISC Type: UNKNOWN http://www.spidynamics.com/sunone_alert.html Source: XF Type: UNKNOWN sunone-http-error-xss(12095) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |