Sun Java System Messenger Express Cross-Site Scripting Vulnerability
BID:20832
Info
Sun Java System Messenger Express Cross-Site Scripting Vulnerability
| Bugtraq ID: | 20832 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5653 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2006 12:00AM |
| Updated: | May 31 2007 12:21AM |
| Credit: | Handrix <[email protected]> discovered this issue. |
| Vulnerable: |
Sun Java System Messenger Express 6 Sun Java System Messenger Express 0 Sun Java System Messaging Server 6.3 Sun Java System Messaging Server 6.2 Sun Java System Messaging Server 6.1 Sun Java System Messaging Server 6.0 |
| Not Vulnerable: | |
Discussion
Sun Java System Messenger Express Cross-Site Scripting Vulnerability
Sun Java System Messenger Express is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Specific information regarding affected versions of Sun Java System Messenger Express is not currently available; this BID will be updated as more information is disclosed.
Sun Java System Messenger Express is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Specific information regarding affected versions of Sun Java System Messenger Express is not currently available; this BID will be updated as more information is disclosed.
Exploit / POC
Sun Java System Messenger Express Cross-Site Scripting Vulnerability
Attackers can use a web client to exploit this issue.
The following URI demonstrates this issue:
Attackers can use a web client to exploit this issue.
The following URI demonstrates this issue:
Solution / Fix
Sun Java System Messenger Express Cross-Site Scripting Vulnerability
Solution:
The vendor released an updated advisory and fixes to address this issue. Please see the references for more information.
Solution:
The vendor released an updated advisory and fixes to address this issue. Please see the references for more information.