20060509 IBM Websphere Application Server Multiple Vulnerabilitiesmailing list
http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html CVE-2006-2431
IBM Websphere 6.0 - 'Faultactor' Cross-Site Scripting
Record summary
CVE-2006-2431 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM Websphere 6.0 - 'Faultactor' Cross-Site ScriptingExploitDB exploitby Nuri FattahNot analyzed1 file
References
Showing 12 of 1720032Third-party advisory
http://secunia.com/advisories/20032 910Third-party advisory
http://securityreason.com/securityalert/910 1017170vdb entry
http://securitytracker.com/id?1017170 PK22416Vendor advisory
http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang= www-1.ibm.comConfirmation
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064 www-1.ibm.comConfirmation
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012163 PK16602Vendor advisory
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16602&apar=only PK26181Vendor advisory
http://www-1.ibm.com/support/search.wss?rs=0&q=PK26181&apar=only 20061107 Minimizing error cascades in vulnerability information managementmailing list
http://www.attrition.org/pipermail/vim/2006-November/001112.html niscc.gov.uk
http://www.niscc.gov.uk/niscc/docs/re-20061031-00727.pdf?lang=en 25371vdb entry
http://www.osvdb.org/25371