Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.Referenceshttp://www.securitytracker.com/id?1019452http://www.vupen.com/english/advisories/2008/0613http://secunia.com/advisories/29041http://dev2dev.bea.com/pub/advisory/261