Record summary

CVE-2006-2431 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM Websphere 6.0 - 'Faultactor' Cross-Site ScriptingExploitDB exploitby Nuri FattahNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 17