Loading
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows.
Cite this page
CVE-2008-0866. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2008-0866
Use CWE-79, Bea vendor hub and Weblogic Workshop product page to widen CVE-2008-0866 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-2705, CVE-2007-5576 and CVE-2008-0869 for nearby disclosures in the same product family.