IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
BID:27665
Info
IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
| Bugtraq ID: | 27665 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0717 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
IBM Websphere Edge server Caching proxy 6.0.2 IBM Websphere Edge server Caching proxy 6.0.1 IBM Websphere Edge server Caching proxy 5.1.1 IBM Websphere Edge server Caching proxy 6.1 IBM Websphere Edge server Caching proxy 6.0 IBM Websphere Edge server Caching proxy 5.1 |
| Not Vulnerable: |
IBM Websphere Edge server Caching proxy 6.1 .15 IBM Websphere Edge server Caching proxy 6.0.2 .26 IBM Websphere Edge server Caching proxy 5.1.1 .38 |
Discussion
IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
IBM WebSphere Edge Server Caching Proxy is prone to a cross-site scripting vulnerability that affects the caching proxy server because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The vulnerability affects Caching Proxy 5.1, 5.1.1, 6.0, 6.0.1, 6.0.2, and 6.1. Other versions may also be affected.
IBM WebSphere Edge Server Caching Proxy is prone to a cross-site scripting vulnerability that affects the caching proxy server because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The vulnerability affects Caching Proxy 5.1, 5.1.1, 6.0, 6.0.1, 6.0.2, and 6.1. Other versions may also be affected.
Exploit / POC
IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the vendor references for more information.
Solution:
The vendor has released fixes to address this issue. Please see the vendor references for more information.
References
IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability
References:
References: