cbcvebase.
CVE-2006-2501
published 2006-05-20

CVE-2006-2501: Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7…

PriorityP425medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.40%
87.4th percentile
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages.

Affected

8 ranges
VendorProductVersion rangeFixed in
sunjava_system_application_server<= 7.0
sunjava_system_web_server<= 6.1
sunjava_system_web_server
sunone_application_server<= 7.0
sunone_application_server
sunone_application_server
sunone_web_server<= 6.0
sunone_web_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.