Back
CVE-2003-0413
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.
Published: Jun 30, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| sun | one_application_server | 7.0 |
GitHub Security Advisory GHSA-7vrv-hpp3-h923
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE...
References (18)
- http://marc.info/?l=bugtraq&m=105409846029475&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&zone_32=category%3Asecurity Patch, Vendor Advisory
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1
- http://www.ciac.org/ciac/bulletins/n-103.shtml Patch, Vendor Advisory
- http://www.iss.net/security_center/static/12095.php Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7710 Exploit, Patch, Vendor Advisory
- http://www.spidynamics.com/sunone_alert.html
- http://marc.info/?l=bugtraq&m=105409846029475&w=2
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&zone_32=category%3Asecurity Patch, Vendor Advisory
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1
- http://www.ciac.org/ciac/bulletins/n-103.shtml Patch, Vendor Advisory
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
6.74%
Top 7% most likely to be exploited
Threat Score
29.2 / 100
Data Sources
NVD
EPSS
GitHub