Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800812
Kategorie:Web Servers
Titel:Sun Java System Web Proxy Server 6.1 < 6.1 SP11 XSS Vulnerability
Zusammenfassung:Sun Java Web Server is prone to a cross-site scripting (XSS); vulnerability.
Beschreibung:Summary:
Sun Java Web Server is prone to a cross-site scripting (XSS)
vulnerability.

Vulnerability Insight:
The Flaw is due to error in 'Reverse Proxy Plug-in' which is not
properly sanitized the input data before being returned to the user. This can be exploited to
inject arbitrary web script or HTML via the query string in situations that result in a 502
Gateway error.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary
code, gain sensitive information by conducting XSS attacks in the context of an affected site.

Affected Software/OS:
Sun Java System Web Server versions 6.1 before 6.1 SP11.

Solution:
Update to version 6.1 SP11 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 35204
Common Vulnerability Exposure (CVE) ID: CVE-2009-1934
http://www.securityfocus.com/bid/35204
http://osvdb.org/54872
http://www.securitytracker.com/id?1022334
http://secunia.com/advisories/35338
http://sunsolve.sun.com/search/document.do?assetkey=1-66-259588-1
http://www.vupen.com/english/advisories/2009/1500
XForce ISS Database: jsws-reverseproxyplugin-xss(50951)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50951
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.