4.3
CVSSv2

CVE-2003-0624

Published: 01/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and previous versions allows remote malicious users to inject malicious web script via the person parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server

bea weblogic server 3.1.8

Exploits

source: wwwsecurityfocuscom/bid/8938/info It has been reported that BEA WebLogic InteractiveQueryjsp example application is prone to a cross-site scripting vulnerability The issue is reported to exist due insufficient sanitization of user-supplied data in an initialization argument called 'person' It has been reported that if an invali ...