CVE-2008-2518: XSS
Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the next parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2518?
CVE-2008-2518 is classified as a medium severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2008-2518?
To fix CVE-2008-2518, upgrade to Sun Java System Web Server 6.1 Service Pack 9 or later, or 7.0 Update 3 or later.
What types of attacks can exploit CVE-2008-2518?
CVE-2008-2518 can be exploited to execute arbitrary web scripts or HTML through cross-site scripting attacks.
Which versions of Sun Java System Web Server are affected by CVE-2008-2518?
CVE-2008-2518 affects Sun Java System Web Server versions 6.1 prior to SP9 and 7.0 prior to Update 3.
Are there any workarounds for CVE-2008-2518?
Temporary workarounds for CVE-2008-2518 include validating and sanitizing user input in the advanced search mechanism.