Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere 500 Internal Server Error 跨站脚本攻击漏洞
Vulnerability Description
IBM WebSphere Application Server 5.0.2 及之前版本, 5.1.1.12之前的5.1.x , 以及6.0.2到6.0.2.7版本的 SOAP端口(8880/tcp) 上的500 Internal Server Error 页中存在跨站脚本攻击漏洞。远程攻击者可以借助该页的FAULTACTOR元素中包含的URI,注入任意Web脚本或HTML 。注意: 某些来源称该元素为"faultfactor" ,但这很可能不正确。
CVSS Information
N/A
Vulnerability Type
N/A