6.8
CVE-2007-2119
- EPSS 3.83%
- Published 18.04.2007 18:19:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Application Server Version9.0.4.3
Oracle ≫ Application Server Version10.1.2.0.2
Oracle ≫ Application Server Version10.1.2.2
Oracle ≫ Database Server Version9.2.0.8
Oracle ≫ Database Server Version10.1.0.5
Oracle ≫ Database Server Version10.2.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.83% | 0.877 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|