CVE-2002-2347

Oracle Application Server - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.

Scores

EPSS 0.0037
EPSS Percentile 58.4%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

oracle/application_server
oracle/application_server
oracle/application_server
oracle/application_server

Timeline

Published Dec 31, 2002
Tracked Since Feb 18, 2026