Unrated severityNVD Advisory· Published Jun 26, 2006· Updated Jun 16, 2026
CVE-2006-3225
CVE-2006-3225
Description
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.
Affected products
67 2004Q2 before Update 5+ 4 more
- (no CPE)range: 7 2004Q2 before Update 5
- cpe:2.3:a:sun:java_system_application_server:*:ur4:*:*:*:*:*:*range: <=7.0
- cpe:2.3:a:sun:java_system_application_server:8.1:*:enterprise:*:*:*:*:*
- cpe:2.3:a:sun:one_application_server:*:update_8:*:*:*:*:*:*range: <=7.0
- (no CPE)range: 7 before Update 9
- Range: 8.1 2005 Q1
Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.