CVE-2008-0869
21.02.2008, 01:44
Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
| Vendor | Product | Version |
|---|---|---|
| bea | weblogic_server | 9.0 |
| bea | weblogic_server | 9.1 |
| bea | weblogic_server | 9.2 |
| bea | weblogic_workshop | 8.1:sp2 |
| bea | weblogic_workshop | 8.1:sp3 |
| bea | weblogic_workshop | 8.1:sp4 |
| bea | weblogic_workshop | 8.1:sp5 |
| bea | weblogic_workshop | 8.1:sp6 |
| bea_systems | weblogic | 10.0 |
𝑥
= Vulnerable software versions
References