Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
| Software | From | Fixed in |
|---|---|---|
| ibm / websphere_application_server | 3.5 | 3.5.x |
| ibm / websphere_application_server | 3.0.2 | 3.0.2.x |