CVE

Id
6729  
CVE No.
CVE-2002-2347  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.  
Phase
Assigned (20071029)  
Votes
None (candidate not yet proposed)  
Comments