First published: Tue May 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =7.0 | |
Sun Java System Web Server | =6.1 | |
Sun Java System Web Server | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2166 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2008-2166, upgrade to Sun Java System Web Server 6.1 SP9 or 7.0 Update 2 or later.
CVE-2008-2166 affects Sun Java System Web Server versions 6.1 before SP9 and 7.0 before Update 2.
CVE-2008-2166 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2008-2166 can allow attackers to inject arbitrary web scripts or HTML, potentially compromising security.