CVE-2007-3503

Oracle Jdk - XSS

Title source: rule

Description

The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0106
EPSS Percentile 77.4%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

oracle/jdk
oracle/jdk

Timeline

Published Jun 30, 2007
Tracked Since Feb 18, 2026