OSVDB ID: 3726

Title: BEA WebLogic HTTP TRACE Response XSS

Info

Disclosure

Jan 27, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

WebLogic Server and Express contain a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate HTTP TRACE requests upon submission to the server. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Bea has released a patch to address this vulnerability.

Products

BEA Systems, Inc.

WebLogic Server

5.1 Service Pack 13
6.1 SP6
7.0 SP4
8.1 SP2

WebLogic Express

5.1 Service Pack 13
6.1 SP6
7.0 SP4
8.1 SP2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218