Unrated severityNVD Advisory· Published May 13, 2008· Updated Apr 23, 2026
CVE-2008-2166
CVE-2008-2166
Description
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.
Affected products
11cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*+ 10 more
- cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:hp_ux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:linux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:sparc:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:windows:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:x86:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:x86:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.