Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.
References 10 Total
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- osvdb.org: 20717 vdb-entry
- securityreason.com: 162 third-party-advisory
- exchange.xforce.ibmcloud.com: sap-fameset-systempublic-xss(23027) vdb-entry
- securityfocus.com: 15361 vdb-entry
- secunia.com: 17515 third-party-advisory
- securitytracker.com: 1015174 vdb-entry
- vupen.com: ADV-2005-2361 vdb-entry
- osvdb.org: 20716 vdb-entry
- marc.info: 20051109 CYBSEC - Security Advisory: Multiple XSS in SAP WAS mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 10 Total
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf x_transferred
- osvdb.org: 20717 vdb-entryx_transferred
- securityreason.com: 162 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: sap-fameset-systempublic-xss(23027) vdb-entryx_transferred
- securityfocus.com: 15361 vdb-entryx_transferred
- secunia.com: 17515 third-party-advisoryx_transferred
- securitytracker.com: 1015174 vdb-entryx_transferred
- vupen.com: ADV-2005-2361 vdb-entryx_transferred
- osvdb.org: 20716 vdb-entryx_transferred
- marc.info: 20051109 CYBSEC - Security Advisory: Multiple XSS in SAP WAS mailing-listx_transferred