1 results (0.005 seconds)

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el componente System Landscape Directory (SLD) v6.4 hasta v7.02 en SAP NetWeaver, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) action sobre testsdic y (2) helpstring sobre paramhelp.jsp. • http://dsecrg.com/pages/vul/show.php?id=168 http://packetstormsecurity.org/1007-advisories/DSECRG-09-068.txt http://secunia.com/advisories/40712 http://www.osvdb.org/66639 http://www.osvdb.org/66640 http://www.vupen.com/english/advisories/2010/1935 https://exchange.xforce.ibmcloud.com/vulnerabilities/60668 https://service.sap.com/sap/support/notes/1416047 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •