CVE-2003-0624
BEA WebLogic Server < 8.1 - Cross-Site Scripting via InteractiveQuery.jsp Person Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0624. PoCs published by Corsaire Limited.
AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in BEA WebLogic's InteractiveQuery.jsp example application. The vulnerability arises from insufficient sanitization of the 'person' parameter, allowing arbitrary script execution in the context of a user's browser.
Description
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
Exploits (1)
The exploit describes a cross-site scripting (XSS) vulnerability in BEA WebLogic's InteractiveQuery.jsp example application. The vulnerability arises from insufficient sanitization of the 'person' parameter, allowing arbitrary script execution in the context of a user's browser.