header-logo
Suggest Exploit
vendor:
Sun Java System Calendar Express Web Server
by:
Core Security Technologies - CoreLabs Advisory
7.5
CVSS
HIGH
Denial of service (DoS), Cross site scripting (XSS)
79, 79, 79
CWE
Product Name: Sun Java System Calendar Express Web Server
Affected Version From: Sun ONE Calendar Server 6.0
Affected Version To: Sun Java System Calendar Server 6.3-7.01 (built Feb 20 2008)
Patch Exists: Yes
Related CWE: N/A
CPE: Sun:Calendar_Server
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009

Multiple vulnerabilities in Sun Calendar Express Web Server

Several vulnerabilities have been discovered in Sun Java System Calendar Express web server. First, an attacker can crash the web server creating a Denial of Service condition by simply requesting certain URL twice. Second, several Cross-site scripting vulnerabilities were found in the following files/urls: 'https://<server>:3443/login.wcap' and 'https://<server>:3443/command.shtml'. Cross-site scripting (XSS) vulnerabilities allow an attacker to execute arbitrary scripting code in the context of the user browser (in the vulnerable application's domain). For example, an attacker could exploit an XSS vulnerability to steal user cookies (and then impersonate the legitimate user) or fake a page requesting information to the user (i.e. credentials). This vulnerability occurs when user-supplied data is displayed without encoding.

Mitigation:

Sun has published patches and a Sun alert for these vulnerabilities.
Source

Exploit-DB raw data: