Cross-Site Scripting in Sun Java System Web Proxy Server by Sun Microsystems
CVE-2007-6569
Currently unrated
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 28 December 2007
Summary
A cross-site scripting (XSS) vulnerability exists in the View Error Log feature of Sun Java System Web Proxy Server versions prior to 4.0.6. This flaw allows remote attackers to inject arbitrary web scripts or HTML into the error log via unspecified methods. When exploited, this vulnerability can enable attackers to execute malicious scripts in the context of the user's session, posing significant security risks to the affected applications and their users.
References
Timeline
Vulnerability published
Vulnerability Reserved