5.8
CVSSv2

CVE-2004-2763

Published: 01/06/2009 Updated: 02/06/2009
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote malicious users to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

Vulnerable Product Search on Vulmon Subscribe to Product

sun iplanet web server 4.1

sun one web server 4.1

sun one web server 6.1

sun iplanet web server 6.0

sun one web server 6.0