Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2004-2763

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

  • Published: Jun 2, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2004-2763
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:N
Software From Fixed in
sun / one_web_server 4.1 4.1.x
sun / one_web_server 6.0-sp3 6.0-sp3.x
sun / one_web_server 6.1-sp1 6.1-sp1.x
sun / iplanet_web_server 4.1-sp9 4.1-sp9.x
sun / iplanet_web_server 6.0-sp1 6.0-sp1.x
sun / one_web_server 4.1-sp11 4.1-sp11.x
sun / iplanet_web_server 4.1-sp4 4.1-sp4.x
sun / iplanet_web_server 4.1-sp10 4.1-sp10.x
sun / iplanet_web_server 6.0-sp2 6.0-sp2.x
sun / iplanet_web_server 4.1-sp1 4.1-sp1.x
sun / iplanet_web_server 4.1-sp7 4.1-sp7.x
sun / one_web_server 6.0-sp5 6.0-sp5.x
sun / iplanet_web_server 6.0-sp4 6.0-sp4.x
sun / iplanet_web_server 4.1-sp3 4.1-sp3.x
sun / iplanet_web_server 4.1-sp8 4.1-sp8.x
sun / one_web_server 4.1-sp3 4.1-sp3.x
sun / one_web_server 4.1-sp1 4.1-sp1.x
sun / iplanet_web_server 4.1-sp5 4.1-sp5.x
sun / iplanet_web_server 4.1-sp11 4.1-sp11.x
sun / one_web_server 4.1-sp6 4.1-sp6.x
sun / one_web_server 4.1-sp5 4.1-sp5.x
sun / one_web_server 6.1-sp2 6.1-sp2.x
sun / one_web_server 4.1-sp2 4.1-sp2.x
sun / one_web_server 4.1-sp9 4.1-sp9.x
sun / iplanet_web_server 4.1-sp2 4.1-sp2.x
sun / iplanet_web_server 4.1-sp6 4.1-sp6.x
sun / one_web_server 4.1-sp8 4.1-sp8.x
sun / one_web_server 4.1-sp7 4.1-sp7.x
sun / one_web_server 4.1-sp12 4.1-sp12.x
sun / iplanet_web_server 6.0-sp3 6.0-sp3.x
sun / iplanet_web_server 6.0-sp5 6.0-sp5.x
sun / one_web_server 6.0-sp4 6.0-sp4.x
sun / iplanet_web_server 4.1-sp12 4.1-sp12.x
sun / one_web_server 4.1-sp4 4.1-sp4.x
sun / one_web_server 4.1-sp10 4.1-sp10.x