header-logo
Suggest Exploit
vendor:
Weblogic
by:
CERT Coordination Center, DoD-CERT, JTF-CND, FedCIRC, NIPC
7.5
CVSS
HIGH
Client-side code execution
CWE
Product Name: Weblogic
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2000

Malicious HTML Tags Embedded in Client Web Requests

This vulnerability allows an attacker to execute malicious code on client-side browsers by exploiting the scripting capabilities of rogue websites. By uploading JSP or JHTML code to a vulnerable web server, an attacker can execute arbitrary code.

Mitigation:

Implement input validation and sanitization to prevent malicious code execution. Regularly update and patch web servers.
Source

Exploit-DB raw data: