Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
BID:15783
Info
Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15783 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2005 12:00AM |
| Updated: | Dec 09 2005 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
Computer Associates CleverPath Portal 4.7 |
| Not Vulnerable: | |
Discussion
Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
Computer Associates CleverPath Portal is prone to a cross-site scripting vulnerability in the login page.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Computer Associates CleverPath Portal is prone to a cross-site scripting vulnerability in the login page.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
Solution:
A fix is available:
Computer Associates CleverPath Portal 4.7
Solution:
A fix is available:
Computer Associates CleverPath Portal 4.7
-
Computer Associates QI70871
http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=QI7087 1
References
Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
References:
References:
- CleverPath Portal (Computer Associates)
- QI70871 (Computer Associates)