CVE-2007-0628: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0628?
CVE-2007-0628 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-0628?
To fix CVE-2007-0628, upgrade the affected Sun Java System Access Manager to a version later than 20070129.
What software is affected by CVE-2007-0628?
CVE-2007-0628 affects Sun Java System Access Manager versions 6.1, 6.2, 6.3, and 7.0.
What attacks can be executed through CVE-2007-0628?
CVE-2007-0628 allows remote attackers to inject arbitrary web scripts or HTML into the application.
When was CVE-2007-0628 reported?
CVE-2007-0628 was reported prior to its fix release on January 29, 2007.