>> BEA WebLogic Unspecified Cross Site Scripting Vulnerabilities
Title : BEA WebLogic Unspecified Cross Site Scripting Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0607 CVE ID : CVE-2005-1747 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-24
Technical Description
Multiple vulnerabilities were identified in BEA WebLogic Server and WebLogic Express, which may be exploited by malicious users to conduct cross site scripting attacks. This flaw is due to input validation errors which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser. No further details have been disclosed.