CVE-2003-0624: XSS
Published Nov 5, 2003
·Updated
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
Affected Software
2 affected components
Bea WebLogic Server<=8.1
Bea WebLogic Server=3.1.8
Remediation
Event History
Nov 5, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 1, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0624?
CVE-2003-0624 has a medium severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2003-0624?
To fix CVE-2003-0624, upgrade to a version of BEA WebLogic Server later than 8.1 or apply available patches.
3
What types of attacks can CVE-2003-0624 enable?
CVE-2003-0624 can enable remote attackers to execute arbitrary web scripts in the context of vulnerable applications.
4
Which versions of WebLogic Server are affected by CVE-2003-0624?
CVE-2003-0624 affects BEA WebLogic Server versions up to and including 8.1 and version 3.1.8.
5
Is user input related to the vulnerability in CVE-2003-0624?
Yes, the vulnerability in CVE-2003-0624 arises from improper handling of the 'person' parameter in user input.