CVE-2008-0866
Summary
| CVE | CVE-2008-0866 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-21 01:44:00 UTC |
| Updated | 2011-03-08 03:05:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bea | Weblogic Workshop | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp3 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp4 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp5 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp2 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp3 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp4 | All | All |
| Application | Bea | Weblogic Workshop | 8.1 | sp5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Fusion Middleware Technologies | BEA | dev2dev.bea.com | |
| WebLogic Workshop NetUI Input Validation Bugs Permit Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.