Vulnerabilities > CVE-2007-1504 - Cross-Site Scripting vulnerability in iNTERSTAGE Application Server Standard Edition
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
fujitsu
Summary
Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes.
Vulnerable Configurations
References
- http://jvn.jp/jp/JVN%2383832818/index.html
- http://osvdb.org/34276
- http://secunia.com/advisories/24508
- http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html
- http://www.securityfocus.com/bid/23020
- http://www.vupen.com/english/advisories/2007/0996
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33099