CVE-2007-6569

Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sun:java_system_web_proxy_server:*:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:*:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:*:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:*:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:*:*:x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:3.6:*:aix:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:3.6:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:3.6:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_proxy_server:3.6:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:6.1:*:x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:x86:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://docs.sun.com/app/docs/doc/820-2499/aeaaa?a=view - () http://docs.sun.com/app/docs/doc/820-2499/aeaaa?a=view -
References () http://secunia.com/advisories/28186 - Patch () http://secunia.com/advisories/28186 - Patch
References () http://secunia.com/advisories/28216 - () http://secunia.com/advisories/28216 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-103002-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-26-103002-1 - Patch
References () http://www.securityfocus.com/bid/26978 - Patch () http://www.securityfocus.com/bid/26978 - Patch
References () http://www.vupen.com/english/advisories/2007/4313 - () http://www.vupen.com/english/advisories/2007/4313 -

Information

Published : 2007-12-28 21:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6569

Mitre link : CVE-2007-6569

CVE.ORG link : CVE-2007-6569


JSON object : View

Products Affected

sun

  • java_system_web_proxy_server
  • java_system_web_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')