First published: Wed Nov 05 2003(Updated: )
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle WebLogic Server | <=8.1 | |
Oracle WebLogic Server | =3.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0624 has a medium severity level due to its potential for cross-site scripting attacks.
To fix CVE-2003-0624, upgrade to a version of BEA WebLogic Server later than 8.1 or apply available patches.
CVE-2003-0624 can enable remote attackers to execute arbitrary web scripts in the context of vulnerable applications.
CVE-2003-0624 affects BEA WebLogic Server versions up to and including 8.1 and version 3.1.8.
Yes, the vulnerability in CVE-2003-0624 arises from improper handling of the 'person' parameter in user input.