Vulnerabilities > CVE-2005-3635 - Cross-Site Scripting vulnerability in SAP Web Application Server

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
sap
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

Exploit-Db

descriptionSAP Web Application Server 6.x/7.0 frameset.htm sap-syscmd Parameter XSS. CVE-2005-3635. Webapps exploit for php platform
idEDB-ID:26487
last seen2016-02-03
modified2005-11-09
published2005-11-09
reporterLeandro Meiners
sourcehttps://www.exploit-db.com/download/26487/
titleSAP Web Application Server 6.x/7.0 frameset.htm sap-syscmd Parameter XSS