Summary
Detail | |||
---|---|---|---|
Vendor | Sun | First view | 2009-05-21 |
Product | Java System Communications Express | Last view | 2009-05-21 |
Version | 6.3 | Type | Application |
Update | * | ||
Edition | linux | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:sun:java_system_communications_express |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.3 | 2009-05-21 | CVE-2009-1729 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
54610 | Sun Java System Communications Express uwc/abs/search.xml abperson_displayNam... |
54609 | Sun Java System Communications Express uwc/base/UWCMain URL Parameter XSS |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2007-04-19 | Name: The remote host is missing Sun Security Patch number 122793-36 File: solaris10_122793.nasl - Type: ACT_GATHER_INFO |
2007-04-19 | Name: The remote host is missing Sun Security Patch number 122794-36 File: solaris10_x86_122794.nasl - Type: ACT_GATHER_INFO |
2007-04-19 | Name: The remote host is missing Sun Security Patch number 122793-36 File: solaris9_122793.nasl - Type: ACT_GATHER_INFO |
2007-04-19 | Name: The remote host is missing Sun Security Patch number 122794-36 File: solaris9_x86_122794.nasl - Type: ACT_GATHER_INFO |