4.3

CVE-2009-1934

Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary web script or HTML via the query string in situations that result in a 502 Gateway error.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SunJava System Web Server Version6.1 Updatesp10 Editionaix
SunJava System Web Server Version6.1 Updatesp4 Editionaix
SunJava System Web Server Version6.1 Updatesp5 Editionaix
SunJava System Web Server Version6.1 Updatesp6 Editionaix
SunJava System Web Server Version6.1 Updatesp7 Editionaix
SunJava System Web Server Version6.1 Updatesp8 Editionaix
SunJava System Web Server Version6.1 Updatesp9 Editionaix
SunOne Web Server Version6.1 Editionaix
SunOne Web Server Version6.1 Updatesp1 Editionaix
SunOne Web Server Version6.1 Updatesp2 Editionaix
SunOne Web Server Version6.1 Updatesp3 Editionaix
SunJava System Web Server Version6.1 Updatesp10 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp4 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp5 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp6 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp7 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp8 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp9 Editionhp_ux
SunOne Web Server Version6.1 Editionhp_ux
SunOne Web Server Version6.1 Updatesp1 Editionhp_ux
SunOne Web Server Version6.1 Updatesp2 Editionhp_ux
SunOne Web Server Version6.1 Updatesp3 Editionhp_ux
SunJava System Web Server Version6.1 Updatesp10 Editionlinux
SunJava System Web Server Version6.1 Updatesp4 Editionlinux
SunJava System Web Server Version6.1 Updatesp5 Editionlinux
SunJava System Web Server Version6.1 Updatesp6 Editionlinux
SunJava System Web Server Version6.1 Updatesp7 Editionlinux
SunJava System Web Server Version6.1 Updatesp8 Editionlinux
SunJava System Web Server Version6.1 Updatesp9 Editionlinux
SunOne Web Server Version6.1 Editionlinux
SunOne Web Server Version6.1 Updatesp1 Editionlinux
SunOne Web Server Version6.1 Updatesp2 Editionlinux
SunOne Web Server Version6.1 Updatesp3 Editionlinux
SunJava System Web Server Version6.1 Updatesp10 Editionwindows
SunJava System Web Server Version6.1 Updatesp4 Editionwindows
SunJava System Web Server Version6.1 Updatesp5 Editionwindows
SunJava System Web Server Version6.1 Updatesp6 Editionwindows
SunJava System Web Server Version6.1 Updatesp7 Editionwindows
SunJava System Web Server Version6.1 Updatesp8 Editionwindows
SunJava System Web Server Version6.1 Updatesp9 Editionwindows
SunOne Web Server Version6.1 Editionwindows
SunOne Web Server Version6.1 Updatesp1 Editionwindows
SunOne Web Server Version6.1 Updatesp2 Editionwindows
SunOne Web Server Version6.1 Updatesp3 Editionwindows
SunJava System Web Server Version6.1 Updatesp10 Editionsparc
SunJava System Web Server Version6.1 Updatesp4 Editionsparc
SunJava System Web Server Version6.1 Updatesp5 Editionsparc
SunJava System Web Server Version6.1 Updatesp6 Editionsparc
SunJava System Web Server Version6.1 Updatesp7 Editionsparc
SunJava System Web Server Version6.1 Updatesp8 Editionsparc
SunJava System Web Server Version6.1 Updatesp9 Editionsparc
SunOne Web Server Version6.1 Editionsparc
SunOne Web Server Version6.1 Updatesp1 Editionsparc
SunOne Web Server Version6.1 Updatesp2 Editionsparc
SunOne Web Server Version6.1 Updatesp3 Editionsparc
SunJava System Web Server Version6.1 Updatesp10 Editionx86
SunJava System Web Server Version6.1 Updatesp4 Editionx86
SunJava System Web Server Version6.1 Updatesp48 Editionx86
SunJava System Web Server Version6.1 Updatesp5 Editionx86
SunJava System Web Server Version6.1 Updatesp6 Editionx86
SunJava System Web Server Version6.1 Updatesp7 Editionx86
SunJava System Web Server Version6.1 Updatesp9 Editionx86
SunOne Web Server Version6.1 Editionx86
SunOne Web Server Version6.1 Updatesp1 Editionx86
SunOne Web Server Version6.1 Updatesp2 Editionx86
SunOne Web Server Version6.1 Updatesp3 Editionx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.67
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.