Description
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.
Affected products
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server6.1 – 6.1
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server7.0 – 7.0
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server8.1 – 8.1
- bea / weblogic_server9.0 – 9.0
- bea / weblogic_server9.1 – 9.1
- bea / weblogic_server10.0 – 10.0
- bea_systems / weblogic_server10.0_mp1 – 10.0_mp1
References
- MISChttp://dev2dev.bea.com/pub/advisory/273
- VENDOR_ADVISORYhttp://secunia.com/advisories/29041
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/0612/references