IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
BID:15929
Info
IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 15929 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | dr_insane is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
IBM Websphere Application Server 6.0 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
IBM WebSphere Application Server sample scripts are prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
Multiple sample scripts are prone to HTML injection vulnerabilities. An attacker can exploit these issues to execute arbitrary HTML or script code in the browser of a user who visits the site in the context of the affected site. The attacker may also be able to modify how the site looks.
IBM WebSphere Application Server sample scripts are prone to multiple HTML injection vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
Multiple sample scripts are prone to HTML injection vulnerabilities. An attacker can exploit these issues to execute arbitrary HTML or script code in the browser of a user who visits the site in the context of the affected site. The attacker may also be able to modify how the site looks.
Exploit / POC
IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM WebSphere Application Server Sample Scripts Multiple HTML Injection Vulnerabilities
References:
References:
- IBM WEBSPHERE 6 Sample scripts Cross site scripting (Packetstorm)
- WebSphere Product Page (IBM)