CVE-2006-6703: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/containertabs.jsp, and other unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6703?
CVE-2006-6703 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-6703?
To mitigate CVE-2006-6703, ensure that you are using the latest patched version of Oracle Portal and sanitize user inputs in applications.
What types of applications are impacted by CVE-2006-6703?
CVE-2006-6703 affects Oracle Portal 9i and 10g applications that process the tc parameter in URLs.
What is the main attack vector for CVE-2006-6703?
The main attack vector for CVE-2006-6703 is via injecting arbitrary JavaScript through the tc parameter in specific JSP files.
Can CVE-2006-6703 be exploited remotely?
Yes, CVE-2006-6703 can be exploited remotely by attackers to execute malicious scripts in the context of the victim's browser.