5.8

CVE-2004-2763

Exploit

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

Data is provided by the National Vulnerability Database (NVD)
SunIplanet Web Server Version4.1 Updatesp1
SunIplanet Web Server Version4.1 Updatesp1 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp10
SunIplanet Web Server Version4.1 Updatesp10 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp11
SunIplanet Web Server Version4.1 Updatesp11 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp12
SunIplanet Web Server Version4.1 Updatesp12 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp2
SunIplanet Web Server Version4.1 Updatesp2 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp3
SunIplanet Web Server Version4.1 Updatesp3 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp4
SunIplanet Web Server Version4.1 Updatesp4 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp5
SunIplanet Web Server Version4.1 Updatesp5 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp6
SunIplanet Web Server Version4.1 Updatesp6 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp7
SunIplanet Web Server Version4.1 Updatesp7 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp8
SunIplanet Web Server Version4.1 Updatesp8 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp9
SunIplanet Web Server Version4.1 Updatesp9 Editionenterprise
SunIplanet Web Server Version6.0 Updatesp1
SunIplanet Web Server Version6.0 Updatesp2
SunIplanet Web Server Version6.0 Updatesp3
SunIplanet Web Server Version6.0 Updatesp4
SunIplanet Web Server Version6.0 Updatesp5
SunOne Web Server Version4.1
SunOne Web Server Version4.1 Updatesp1
SunOne Web Server Version4.1 Updatesp10
SunOne Web Server Version4.1 Updatesp11
SunOne Web Server Version4.1 Updatesp12
SunOne Web Server Version4.1 Updatesp2
SunOne Web Server Version4.1 Updatesp3
SunOne Web Server Version4.1 Updatesp4
SunOne Web Server Version4.1 Updatesp5
SunOne Web Server Version4.1 Updatesp6
SunOne Web Server Version4.1 Updatesp7
SunOne Web Server Version4.1 Updatesp8
SunOne Web Server Version4.1 Updatesp9
SunOne Web Server Version6.0 Updatesp3
SunOne Web Server Version6.0 Updatesp4
SunOne Web Server Version6.0 Updatesp5
SunOne Web Server Version6.1 Updatesp1
SunOne Web Server Version6.1 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.65% 0.699
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N