6.8
CVSSv2

CVE-2003-0749

Published: 20/10/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote malicious users to insert arbitrary web script and steal cookies via the ~service parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sap internet transaction server 4620.2.0.323011

Exploits

source: wwwsecurityfocuscom/bid/8517/info The 'wgatedll' componenet of SAP Internet Transaction Server has been reported prone to cross-site scripting attacks The issue occurs due to a lack of sufficient sanitization performed on data supplied to the 'wgatedll' library Exploitation could allow theft of cookie-based authentication cred ...