Sun ONE and Sun Java System Applications Error Page Cross-Site Scripting Vulnerability

BID:18035

CVE-2006-2501 |

Info

Sun ONE and Sun Java System Applications Error Page Cross-Site Scripting Vulnerability

Bugtraq ID: 18035
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: May 19 2006 12:00AM
Updated: May 19 2006 05:58PM
Credit: These issues were disclosed by the vendor.
Vulnerable: Sun ONE Web Server 6.0 SP9
Sun ONE Web Server 6.0 SP8
Sun ONE Web Server 6.0 SP7
Sun ONE Web Server 6.0 SP6
Sun ONE Web Server 6.0 SP5
Sun ONE Web Server 6.0 SP4
Sun ONE Web Server 6.0 SP3
Sun ONE Web Server 6.0 SP2
Sun ONE Web Server 6.0 SP1
Sun ONE Web Server 6.0
Sun ONE Web Server 4.1 SP9
Sun ONE Web Server 4.1 SP8
Sun ONE Web Server 4.1 SP7
Sun ONE Web Server 4.1 SP6
Sun ONE Web Server 4.1 SP5
Sun ONE Web Server 4.1 SP5
Sun ONE Web Server 4.1 SP4
Sun ONE Web Server 4.1 SP3
Sun ONE Web Server 4.1 SP2
Sun ONE Web Server 4.1 SP14
Sun ONE Web Server 4.1 SP13
Sun ONE Web Server 4.1 SP12
Sun ONE Web Server 4.1 SP11
Sun ONE Web Server 4.1 SP10
Sun ONE Web Server 4.1 SP1
Sun ONE Web Server 4.1
Sun ONE Application Server 7.0 UR6 Standard Edition
Sun ONE Application Server 7.0 UR6 Platform Edition
Sun ONE Application Server 7.0 UR2 Upgrade Standard
Sun ONE Application Server 7.0 UR2 Upgrade Platform
Sun ONE Application Server 7.0 UR2 Standard Edition
Sun ONE Application Server 7.0 UR2 Platform Edition
Sun ONE Application Server 7.0 UR1 Standard Edition
Sun ONE Application Server 7.0 UR1 Platform Edition
Sun ONE Application Server 7.0 Standard Edition
Sun ONE Application Server 7.0 Platform Edition
Sun ONE Application Server 6.5 SP1 MU7
Sun ONE Application Server 6.5 SP1 MU6
Sun ONE Application Server 6.5 SP1 MU5
Sun ONE Application Server 6.5 SP1 MU4
Sun ONE Application Server 6.5 SP1 MU3
Sun ONE Application Server 6.5 SP1 MU2
Sun ONE Application Server 6.5 SP1 MU1
Sun ONE Application Server 6.5 SP1
Sun ONE Application Server 6.5 MU3
Sun ONE Application Server 6.5 MU2
Sun ONE Application Server 6.5 MU1
Sun ONE Application Server 6.5
Sun ONE Application Server 6.0 SP4
Sun ONE Application Server 6.0 SP3
Sun ONE Application Server 6.0 SP2
Sun ONE Application Server 6.0 SP1
Sun ONE Application Server 6.0
Sun Java System Web Server 6.1 SP4
Sun Java System Web Server 6.1 SP3
Sun Java System Web Server 6.1 SP2
Sun Java System Web Server 6.1 SP1
Sun Java System Web Server 6.1
Sun Java System Web Server 6.0 SP8
Sun Java System Web Server 6.0 SP7
Sun Java System Web Server 6.0 SP6
Sun Java System Web Server 6.0 SP5
Sun Java System Web Server 6.0 SP4
Sun Java System Web Server 6.0 SP3
Sun Java System Web Server 6.0 SP2
Sun Java System Web Server 6.0 SP1
Sun Java System Web Server 6.0
Sun Java System Application Server 7.0 UR7 Standard Edition
Sun Java System Application Server 7.0 UR7 Platform Edition
Sun Java System Application Server 7.0 UR6 Standard Edition
Sun Java System Application Server 7.0 UR6 Platform Edition
Sun Java System Application Server 7.0 UR5 Standard Edition
Sun Java System Application Server 7.0 UR5 Platform Edition
Sun Java System Application Server 7.0 UR4
Sun Java System Application Server 7.0 2004Q2 R2 Standard
Sun Java System Application Server 7.0 2004Q2 R2 Enterprise
Sun Java System Application Server 7.0 2004Q2 R1Standard
Sun Java System Application Server 7.0 2004Q2 R1Enterprise
Sun Java System Application Server 7.0 Standard Edition
Sun Java System Application Server 7.0 Platform Edition
Sun Java System Application Server 7.0 Enterprise Edition
Sun Java System Application Server 7.0 2004Q2
Not Vulnerable: Sun ONE Web Server 6.0 SP10
Sun ONE Application Server 7.0 UR7 Standard Edition
Sun ONE Application Server 7.0 UR7 Platform Edition
Sun Java System Web Server 6.1 SP5
Sun Java System Application Server 7.0 2004Q2 R3 Standard
Sun Java System Application Server 7.0 2004Q2 R3 Enterprise

Discussion

Sun ONE and Sun Java System Applications Error Page Cross-Site Scripting Vulnerability

Sun One and Sun Java System applications are prone to a cross-site scripting vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Exploit / POC

Sun ONE and Sun Java System Applications Error Page Cross-Site Scripting Vulnerability

This issue can be exploited through a web client.

Solution / Fix

Sun ONE and Sun Java System Applications Error Page Cross-Site Scripting Vulnerability

Solution:
The vendor has released updates to address this issue.


Sun ONE Web Server 6.0 SP5

Sun ONE Web Server 6.0 SP9

Sun ONE Web Server 6.0 SP4

Sun ONE Web Server 6.0 SP7

Sun ONE Web Server 6.0 SP6

Sun ONE Web Server 6.0

Sun ONE Web Server 6.0 SP2

Sun ONE Web Server 6.0 SP3

Sun ONE Web Server 6.0 SP8

Sun ONE Web Server 6.0 SP1

Sun Java System Web Server 6.1 SP4

Sun Java System Web Server 6.1 SP3

Sun Java System Web Server 6.1 SP1

Sun Java System Web Server 6.1 SP2

Sun Java System Web Server 6.1

Sun ONE Application Server 7.0 UR1 Platform Edition

Sun ONE Application Server 7.0 UR2 Standard Edition

Sun ONE Application Server 7.0 Standard Edition

Sun Java System Application Server 7.0 2004Q2 R2 Standard

Sun Java System Application Server 7.0 2004Q2 R2 Enterprise

Sun ONE Application Server 7.0 UR6 Standard Edition

Sun ONE Application Server 7.0 Platform Edition

Sun ONE Application Server 7.0 UR2 Platform Edition

Sun Java System Application Server 7.0 2004Q2 R1Enterprise

Sun ONE Application Server 7.0 UR6 Platform Edition

Sun Java System Application Server 7.0 2004Q2 R1Standard

Sun ONE Application Server 7.0 UR2 Upgrade Platform

Sun ONE Application Server 7.0 UR2 Upgrade Standard

Sun ONE Application Server 7.0 UR1 Standard Edition

References

© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report