2.6
CVE-2006-3225
- EPSS 1.98%
- Veröffentlicht 26.06.2006 16:05:00
- Zuletzt bearbeitet 16.06.2026 22:26:39
- Erkennungen
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Java System Application Server Update ur4 Version <= 7.0
Sun ≫ Java System Application Server Version 8.1 Edition enterprise
Sun ≫ One Application Server Update update_8 Version <= 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.98% | 0.785 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/20835
http://securitytracker.com/id?1016378
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102479-1
http://www.securityfocus.com/bid/18635
http://www.vupen.com/english/advisories/2006/2508
https://exchange.xforce.ibmcloud.com/vulnerabilities/27392