CVE-2005-1747
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2005-05-24 CVE Published
- 2005-05-25 CVE Reserved
- 2024-04-30 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=111695844803328&w=2 | Mailing List | |
http://marc.info/?l=bugtraq&m=111695921212456&w=2 | Mailing List | |
http://marc.info/?l=bugtraq&m=111722298705561&w=2 | Mailing List | |
http://marc.info/?l=bugtraq&m=111722380313416&w=2 | Mailing List | |
http://securitytracker.com/id?1014049 | Vdb Entry | |
http://www.acrossecurity.com/aspr/ASPR-2005-05-24-1-PUB.txt | X_refsource_misc | |
http://www.acrossecurity.com/aspr/ASPR-2005-05-24-2-PUB.txt | X_refsource_misc | |
http://www.appsecinc.com/resources/alerts/general/BEA-001.html | X_refsource_misc | |
http://www.appsecinc.com/resources/alerts/general/BEA-002.html | X_refsource_misc | |
http://www.securityfocus.com/bid/13717 | Vdb Entry | |
http://www.vupen.com/english/advisories/2005/0607 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://dev2dev.bea.com/pub/advisory/130 | 2018-10-30 | |
http://secunia.com/advisories/15486 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp1, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.0 Search vendor "Bea" for product "Weblogic Server" and version "6.0" | sp2, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp1, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp2, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp3, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp4, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp5, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp5, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp6 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 6.1 Search vendor "Bea" for product "Weblogic Server" and version "6.1" | sp6, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp1, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp2, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp3, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp4, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0 Search vendor "Bea" for product "Weblogic Server" and version "7.0" | sp5, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp1, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp2, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 7.0.0.1 Search vendor "Bea" for product "Weblogic Server" and version "7.0.0.1" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | - |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp1 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp1, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp1, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp2 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp2, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp2, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp3 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp3, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp3, win32 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp4 |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp4, express |
Affected
| ||||||
Bea Search vendor "Bea" | Weblogic Server Search vendor "Bea" for product "Weblogic Server" | 8.1 Search vendor "Bea" for product "Weblogic Server" and version "8.1" | sp4, win32 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Portal Search vendor "Oracle" for product "Weblogic Portal" | 8.0 Search vendor "Oracle" for product "Weblogic Portal" and version "8.0" | - |
Affected
|