Lucene search

K
cveMitreCVE-2008-2166
HistoryMay 13, 2008 - 8:20 p.m.

CVE-2008-2166

2008-05-1320:20:00
CWE-79
mitre
web.nvd.nist.gov
23
cve-2008-2166
cross-site scripting
xss
sun java system
web server 6.1
web server 7.0
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.003

Percentile

66.7%

Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.

Affected configurations

Nvd
Node
sunjava_system_web_serverMatch6.1aix
OR
sunjava_system_web_serverMatch6.1hp_ux
OR
sunjava_system_web_serverMatch6.1linux
OR
sunjava_system_web_serverMatch6.1sparc
OR
sunjava_system_web_serverMatch6.1windows
OR
sunjava_system_web_serverMatch6.1x86
OR
sunjava_system_web_serverMatch7.0hp_ux
OR
sunjava_system_web_serverMatch7.0linux
OR
sunjava_system_web_serverMatch7.0sparc
OR
sunjava_system_web_serverMatch7.0windows
OR
sunjava_system_web_serverMatch7.0x86
VendorProductVersionCPE
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:hp_ux:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:linux:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:sparc:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:windows:*:*:*:*:*
sunjava_system_web_server6.1cpe:2.3:a:sun:java_system_web_server:6.1:*:x86:*:*:*:*:*
sunjava_system_web_server7.0cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
sunjava_system_web_server7.0cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
sunjava_system_web_server7.0cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
sunjava_system_web_server7.0cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.003

Percentile

66.7%

Related for CVE-2008-2166