关键信息 漏洞ID: CVE-2008-5266 CVSS 2.0 Base Score: 4.3 - Access Vector: Network - Access Complexity: Medium - Authentication: None - Confidentiality Impact: None - Integrity Impact: Partial - Availability Impact: None CVSS 2.0 Temporal Score: 3.7 - Exploitability: High - Remediation Level: Official Fix - Report Confidence: Confirmed Consequences: - Gain Access Remedy: - Apply the patch for this vulnerability, available from the GlassFish Web site. See References. Affected Products: - Sun Java System Application Server 9.1_01 - Sun Java System Application Server 9.1_02 - Sun GlassFish 2 ur2 References: - WEBAPPSECURITY'S WEBLOG, June 11, 2008, 2:19 am - GlassFish Web site - BID-29646 - SA30604 Coverage: - Cross_Site_Scripting: Nov 11, 2008 - HTTP_GETargscript: Feb 21, 2005