ID

VAR-E-200511-0203


CVE

cve_id:CVE-2005-3635

Trust: 1.6

sources: EXPLOIT-DB: 26487 // EDBNET: 48460

EDB ID

26487


TITLE

SAP Web Application Server 6.x/7.0 - 'frameset.htm?sap-syscmd' Cross-Site Scripting - PHP webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 26487

DESCRIPTION

SAP Web Application Server 6.x/7.0 - 'frameset.htm?sap-syscmd' Cross-Site Scripting. CVE-2005-3635CVE-20716 . webapps exploit for PHP platform

Trust: 0.6

sources: EXPLOIT-DB: 26487

AFFECTED PRODUCTS

vendor:sapmodel:web application serverscope:eqversion:6.x/7.0

Trust: 1.0

vendor:sapmodel:web application serverscope:eqversion:7.0

Trust: 0.3

vendor:sapmodel:web application serverscope:eqversion:6.40

Trust: 0.3

vendor:sapmodel:web application serverscope:eqversion:6.20

Trust: 0.3

vendor:sapmodel:web application serverscope:eqversion:6.10

Trust: 0.3

sources: BID: 15361 // EXPLOIT-DB: 26487

EXPLOIT

source: https://www.securityfocus.com/bid/15361/info

SAP Web Application Server is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

This issue only affects the BSP runtime of SAP WAS.

http://www.example.com/sap/bc/BSp/sap/menu/fameset.htm?sap-sessioncmd=open&sap-syscmd=%3Cscript%3Ealert('xss')%3C/script%3E

Trust: 1.0

sources: EXPLOIT-DB: 26487

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 26487

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 26487

TYPE

'frameset.htm?sap-syscmd' Cross-Site Scripting

Trust: 1.0

sources: EXPLOIT-DB: 26487

CREDITS

Leandro Meiners

Trust: 0.6

sources: EXPLOIT-DB: 26487

EXTERNAL IDS

db:BIDid:15361

Trust: 1.9

db:NVDid:CVE-2005-3635

Trust: 1.6

db:EXPLOIT-DBid:26487

Trust: 1.6

db:EDBNETid:48460

Trust: 0.6

sources: BID: 15361 // EXPLOIT-DB: 26487 // EDBNET: 48460

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2005-3635

Trust: 1.6

url:https://www.securityfocus.com/bid/15361/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/26487/

Trust: 0.6

url:http://www.sap.com

Trust: 0.3

sources: BID: 15361 // EXPLOIT-DB: 26487 // EDBNET: 48460

SOURCES

db:BIDid:15361
db:EXPLOIT-DBid:26487
db:EDBNETid:48460

LAST UPDATE DATE

2022-07-27T09:23:31.049000+00:00


SOURCES UPDATE DATE

db:BIDid:15361date:2005-11-09T00:00:00

SOURCES RELEASE DATE

db:BIDid:15361date:2005-11-09T00:00:00
db:EXPLOIT-DBid:26487date:2005-11-09T00:00:00
db:EDBNETid:48460date:2005-11-09T00:00:00