Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
{ "nvd_published_at": "2008-03-11T17:44:00Z", "github_reviewed_at": "2022-06-08T22:38:59Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }