CVE-2008-2123
SAP Internet Transaction Server - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in the query string, a different vector than CVE-2006-5114.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Portcullis · textwebappscgi
https://www.exploit-db.com/exploits/31755
exploitdb
WORKING POC
VERIFIED
by Portcullis · textwebappscgi
https://www.exploit-db.com/exploits/31754
References (6)
Scores
EPSS
0.1646
EPSS Percentile
94.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
sap/internet_transaction_server
Timeline
Published
May 09, 2008
Tracked Since
Feb 18, 2026