← Vulnerability feed

Vulnerability record · CVE-2003-0413 · published 30 June 2003

CVE-2003-0413: Sun one application server vulnerability

Sun · One Application Server

Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.

6.8 CVSS 2.0 Medium EPSS 6.7% · top 6.3%
6.8CVSS 2.0 base score
6.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0413 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2004-0826Mozilla network security services vulnerabilityHeap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified recor…EPSS 23%7.5CVE-2002-0387Sun one application server vulnerabilityBuffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arb…EPSS 3.2%7.2CVE-2003-0414Sun one application server vulnerabilityThe installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users …EPSS 0.38%6.8CVE-2006-6276Sun java system application server http request smuggling vulnerabilityHTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java S…EPSS 3.6%6.8CVE-2006-2501Sun java system application server vulnerabilityCross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application S…EPSS 3.4%5.0CVE-2004-1815Macromedia coldfusion vulnerabilityUnknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote a…EPSS 1.6%5.0CVE-2003-0412Sun one application server vulnerabilitySun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide m…EPSS 1.7%5.0CVE-2002-1042Netscape enterprise server vulnerabilityDirectory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Wi…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2003-0413), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.