6.8

CVE-2006-2501

Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages.

Data is provided by the National Vulnerability Database (NVD)
SunJava System Application Server Updateur2 Editionenterprise Version <= 7.0
SunJava System Application Server Updateur2 Editionstandard Version <= 7.0
SunJava System Web Server Updatesp4 Version <= 6.1
SunJava System Web Server Version6.1
SunJava System Web Server Version6.1 Updatesp1
SunJava System Web Server Version6.1 Updatesp2
SunJava System Web Server Version6.1 Updatesp3
SunOne Application Server Updateupdate_6 Editionplatform Version <= 7.0
SunOne Application Server Updateupdate_6 Editionstandard Version <= 7.0
SunOne Application Server Version6.0
SunOne Application Server Version6.0 Updatesp1
SunOne Application Server Version6.0 Updatesp2
SunOne Application Server Version7.0 Editionplatform
SunOne Application Server Version7.0 Editionstandard
SunOne Web Server Updatesp9 Version <= 6.0
SunOne Web Server Version6.0 Updatesp3
SunOne Web Server Version6.0 Updatesp4
SunOne Web Server Version6.0 Updatesp5
SunOne Web Server Version6.0 Updatesp7
SunOne Web Server Version6.0 Updatesp8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.44% 0.907
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P