Cross-site Scripting Vulnerability in SAP Internet Transaction Server
CVE-2003-0749

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
20 October 2003

What is CVE-2003-0749?

A cross-site scripting vulnerability exists in the wgate.dll component of SAP Internet Transaction Server version 4620.2.0.323011. This flaw allows remote attackers to inject arbitrary web scripts through the ~service parameter, enabling them to execute malicious scripts within the context of a user's browser. This can lead to the theft of sensitive cookies and user information, posing significant risks to the affected systems.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.