Cross-Site Scripting in Sun Java System Web Proxy Server by Sun Microsystems
CVE-2007-6569

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
28 December 2007

Summary

A cross-site scripting (XSS) vulnerability exists in the View Error Log feature of Sun Java System Web Proxy Server versions prior to 4.0.6. This flaw allows remote attackers to inject arbitrary web scripts or HTML into the error log via unspecified methods. When exploited, this vulnerability can enable attackers to execute malicious scripts in the context of the user's session, posing significant security risks to the affected applications and their users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.