First published: Fri Dec 28 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Web Server | =6.0-sp9 | |
Sun Java System Web Server | =6.1-sp1 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp1 | |
Sun Java System Web Server | =6.1-sp6 | |
Sun Java System Web Server | =6.0-sp1 | |
Oracle Sun Java System Web Proxy Server | =4.0-sp1 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp6 | |
Oracle Sun Java System Web Proxy Server | =4.0.2 | |
Sun Java System Web Server | =6.0-sp10 | |
Sun Java System Web Server | =6.0 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp9 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp2 | |
Sun Java System Web Server | =6.1-sp3 | |
Sun Java System Web Server | =6.0-sp4 | |
Sun Java System Web Server | =6.0-sp6 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp5 | |
Sun Java System Web Server | =6.0-sp2 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp8 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.0-sp7 | |
Sun Java System Web Server | =6.1-sp4 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp7 | |
Oracle Sun Java System Web Proxy Server | =4.0 | |
Oracle Sun Java System Web Proxy Server | =4.0.4 | |
Oracle Sun Java System Web Proxy Server | =4.0.5 | |
Sun Java System Web Server | =6.1-sp5 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp4 | |
Sun Java System Web Server | =7.0 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp3 | |
Sun Java System Web Server | =6.0-sp8 | |
Sun Java System Web Server | =6.0-sp3 | |
Oracle Sun Java System Web Proxy Server | =3.6 | |
Sun Java System Web Server | =6.0-sp5 | |
Oracle Sun Java System Web Proxy Server | =3.6-sp10 | |
Sun Java System Web Server | =6.1-sp2 | |
Sun Java System Web Server | =6.1-sp7 | |
Oracle Sun Java System Web Proxy Server | =4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6571 is classified as a critical cross-site scripting (XSS) vulnerability.
To fix CVE-2007-6571, apply the latest service pack or patch released for Sun Java System Web Proxy Server 3.6.
CVE-2007-6571 affects Sun Java System Web Proxy Server versions prior to SP11, along with certain versions of Sun Java System Web Server.
CVE-2007-6571 allows attackers to inject arbitrary web scripts or HTML into the affected server.
A potential workaround for CVE-2007-6571 is to restrict access to the affected web server until a patch can be applied.