vendor:
Weblogic
by:
CERT Coordination Center, DoD-CERT, JTF-CND, FedCIRC, NIPC
7.5
CVSS
HIGH
Client-side code execution
CWE
Product Name: Weblogic
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2000
Malicious HTML Tags Embedded in Client Web Requests
This vulnerability allows an attacker to execute malicious code on client-side browsers by exploiting the scripting capabilities of rogue websites. By uploading JSP or JHTML code to a vulnerable web server, an attacker can execute arbitrary code.
Mitigation:
Implement input validation and sanitization to prevent malicious code execution. Regularly update and patch web servers.