Vulnerabilities > CVE-2005-3636 - Unspecified vulnerability in SAP web Application Server 6.10
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN sap
exploit available
Summary
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SAP Web Application Server 6.x/7.0 Error Page XSS. CVE-2005-3636. Webapps exploit for php platform |
id | EDB-ID:26486 |
last seen | 2016-02-03 |
modified | 2005-11-09 |
published | 2005-11-09 |
reporter | Leandro Meiners |
source | https://www.exploit-db.com/download/26486/ |
title | SAP Web Application Server 6.x/7.0 Error Page XSS |
References
- http://marc.info/?l=bugtraq&m=113156601505542&w=2
- http://marc.info/?l=bugtraq&m=113156601505542&w=2
- http://secunia.com/advisories/17515/
- http://secunia.com/advisories/17515/
- http://securityreason.com/securityalert/162
- http://securityreason.com/securityalert/162
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.osvdb.org/20715
- http://www.osvdb.org/20715
- http://www.securityfocus.com/bid/15361
- http://www.securityfocus.com/bid/15361
- http://www.securitytracker.com/alerts/2005/Nov/1015174.html
- http://www.securitytracker.com/alerts/2005/Nov/1015174.html
- http://www.vupen.com/english/advisories/2005/2361
- http://www.vupen.com/english/advisories/2005/2361
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23029
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23029