4.3
CVSSv2

CVE-2005-3635

Published: 16/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 up to and including 7.00 allow remote malicious users to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

Vulnerable Product Search on Vulmon Subscribe to Product

sap sap web application server 6.10

sap sap web application server 7.0

sap sap web application server 6.20

sap sap web application server 6.40

Exploits

source: wwwsecurityfocuscom/bid/15361/info SAP Web Application Server is prone to multiple cross-site scripting vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting us ...