Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
Link | Tags |
---|---|
http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html | mailing list |
http://www.securityfocus.com/bid/2969 | patch vendor advisory vdb entry exploit |