cbcvebase.
CVE-2004-2763
published 2009-06-01

CVE-2004-2763: The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote…

PriorityP423medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.18%
80.3th percentile
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmlotus_domino_server
ibmlotus_domino_server
ibmlotus_domino_server
ibmlotus_domino_server
suniplanet_web_server
suniplanet_web_server
sunjava_system_application_server
sunone_web_server
sunone_web_server
sunone_web_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.