First published: Fri Dec 28 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =7.0 | |
Oracle Sun Java System Web Proxy Server | <=4.0.6 | |
Oracle Sun Java System Web Proxy Server | <=4.0.6 | |
Oracle Sun Java System Web Proxy Server | <=4.0.6 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =6.1 | |
Oracle Sun Java System Web Proxy Server | =3.6 | |
Oracle Sun Java System Web Proxy Server | <=4.0.6 | |
Oracle Sun Java System Web Proxy Server | <=4.0.6 | |
Oracle Sun Java System Web Proxy Server | =3.6 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =7.0 | |
Oracle Sun Java System Web Proxy Server | =3.6 | |
Sun Java System Web Server | =6.1 | |
Oracle Sun Java System Web Proxy Server | =3.6 | |
Sun Java System Web Server | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6569 has a moderate severity as it allows for cross-site scripting attacks that can compromise user data.
To fix CVE-2007-6569, upgrade to Sun Java System Web Proxy Server version 4.0.6 or later.
CVE-2007-6569 affects Sun Java System Web Proxy Server versions prior to 4.0.6 and certain versions of Sun Java System Web Server.
Yes, CVE-2007-6569 can be exploited remotely by attackers injecting arbitrary web scripts.
Exploiting CVE-2007-6569 can lead to unauthorized actions being performed on behalf of users, potentially exposing sensitive information.