CVE-2008-0867

BEA Systems Aqualogic Interaction - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

Scores

EPSS 0.0047
EPSS Percentile 64.5%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

bea_systems/aqualogic_interaction
bea_systems/aqualogic_interaction
bea_systems/plumtree_foundation
bea_systems/plumtree_foundation

Timeline

Published Feb 21, 2008
Tracked Since Feb 18, 2026