Unrated severityNVD Advisory· Published May 13, 2008· Updated Jun 16, 2026
CVE-2008-2166
CVE-2008-2166
Description
Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.
Affected products
12cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*+ 11 more
- cpe:2.3:a:sun:java_system_web_server:6.1:*:aix:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:hp_ux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:linux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:sparc:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:windows:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:6.1:*:x86:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
- cpe:2.3:a:sun:java_system_web_server:7.0:*:x86:*:*:*:*:*
- (no CPE)range: <6.1 SP9, <7.0 Update 2
Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.