CVE-2006-2431

IBM Websphere Application Server - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nuri Fattah · textremotemultiple
https://www.exploit-db.com/exploits/28981

Scores

EPSS 0.0144
EPSS Percentile 80.5%

Classification

CWE
CWE-79
Status draft

Affected Products (20)

ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
... and 5 more

Timeline

Published May 17, 2006
Tracked Since Feb 18, 2026