CVE-2006-2431 – IBM Websphere 6.0 - 'Faultactor' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2006-2431
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous. • https://www.exploit-db.com/exploits/28981 http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html http://secunia.com/advisories/20032 http://securityreason.com/securityalert/910 http://securitytracker.com/id?1017170 http://www-1.ibm.com/support/docview.wss?rs=0&dc=DB550&q1=PK16492&uid=swg1PK22416&loc=en_US&cs=utf-8&lang= http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012064 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012163 http://ww • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2006-2434
https://notcve.org/view.php?id=CVE-2006-2434
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace. • http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html http://secunia.com/advisories/20032 http://securityreason.com/securityalert/910 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27006879 http://www.vupen.com/english/advisories/2006/1736 http://www.vupen.com/english/advisories/2006/2552 •
CVE-2006-2436
https://notcve.org/view.php?id=CVE-2006-2436
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges. • http://archives.neohapsis.com/archives/bugtraq/2006-05/0175.html http://secunia.com/advisories/20032 http://securityreason.com/securityalert/910 http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27006881 http://www-1.ibm.com/support/search.wss?rs=0&q=PK17589&apar=only http://www.vupen.com/english/advisories/2006/1736 •
CVE-2006-2342
https://notcve.org/view.php?id=CVE-2006-2342
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root. • http://secunia.com/advisories/20025 http://www-1.ibm.com/support/docview.wss?uid=swg24010245 http://www.osvdb.org/25368 http://www.securityfocus.com/bid/17900 http://www.vupen.com/english/advisories/2006/1724 https://exchange.xforce.ibmcloud.com/vulnerabilities/26312 •
CVE-2006-1619
https://notcve.org/view.php?id=CVE-2006-1619
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header. • http://securitytracker.com/id?1015857 http://www-1.ibm.com/support/docview.wss?uid=swg21053738 http://www.vupen.com/english/advisories/2006/1214 https://exchange.xforce.ibmcloud.com/vulnerabilities/25619 •