Vulnerabilities > CVE-2003-0749 - Cross-Site Scripting vulnerability in SAP Internet Transaction Server 4620.2.0.323011

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
sap
exploit available

Summary

Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.

Vulnerable Configurations

Part Description Count
Application
Sap
1

Exploit-Db

descriptionSAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 Cross Site Scripting Vulnerability. CVE-2003-0749 . Remote exploits for multiple platform
idEDB-ID:23071
last seen2016-02-02
modified2003-08-30
published2003-08-30
reporterMartin Eiszner
sourcehttps://www.exploit-db.com/download/23071/
titleSAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Cross-Site Scripting Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/66179/SAP-07-010.txt
idPACKETSTORM:66179
last seen2016-12-05
published2008-05-09
reporterportcullis-security.com
sourcehttps://packetstormsecurity.com/files/66179/SAP-07-010.txt.html
titleSAP-07-010.txt