CVE-2004-2763
published 2009-06-01CVE-2004-2763: The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote…
PriorityP423medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.18%
80.3th percentile
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_domino_server | — | — |
| ibm | lotus_domino_server | — | — |
| ibm | lotus_domino_server | — | — |
| ibm | lotus_domino_server | — | — |
| sun | iplanet_web_server | — | — |
| sun | iplanet_web_server | — | — |
| sun | java_system_application_server | — | — |
| sun | one_web_server | — | — |
| sun | one_web_server | — | — |
| sun | one_web_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6pv-jvqw-865r: The default configuration of the web server in IBM Lotus Domino Server, possibly 6
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2008-7253 [MEDIUM] GHSA-g6pv-jvqw-865r: The default configuration of the web server in IBM Lotus Domino Server, possibly 6
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
GHSA
GHSA-7g8w-vphh-j565: The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attacke
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2010-0386 [MEDIUM] GHSA-7g8w-vphh-j565: The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attacke
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
GHSA
GHSA-79p6-hxp5-mfcw: The default configuration of Sun ONE/iPlanet Web Server 4
ghsa_unreviewed·2022-04-29
CVE-2004-2763 [MEDIUM] GHSA-79p6-hxp5-mfcw: The default configuration of Sun ONE/iPlanet Web Server 4
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archive.cert.uni-stuttgart.de/uniras/2004/02/msg00007.htmlhttp://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdfhttp://www.kb.cert.org/vuls/id/867593http://archive.cert.uni-stuttgart.de/uniras/2004/02/msg00007.htmlhttp://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdfhttp://www.kb.cert.org/vuls/id/867593
2009-06-01
Published