Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown
CVE-2007-6571
Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
0
Attacker Value
Unknown
CVE-2007-6569
Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
0
Attacker Value
Unknown
CVE-2007-6572
Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.
0
Attacker Value
Unknown
CVE-2007-6570
Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
0
Attacker Value
Unknown
CVE-2007-4164
Disclosure Date: August 07, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.
0
Attacker Value
Unknown
CVE-2007-3715
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
0
Attacker Value
Unknown
CVE-2007-2881
Disclosure Date: May 29, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.
0
Attacker Value
Unknown
CVE-2007-1526
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-1488
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.
0
Attacker Value
Unknown
CVE-2006-6276
Disclosure Date: December 04, 2006 (last updated February 09, 2024)
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
0