Sun Java Server Faces Cross-Site Scripting Vulnerability
BID:28192
Info
Sun Java Server Faces Cross-Site Scripting Vulnerability
| Bugtraq ID: | 28192 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1285 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2008 12:00AM |
| Updated: | Aug 05 2008 02:17PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Sun Java Server Faces 1.2 Redhat JBoss Enterprise Application Platform 4.3 EL5 Redhat JBoss Enterprise Application Platform 4.3 EL4 Redhat JBoss Enterprise Application Platform 4.3 Redhat JBoss Enterprise Application Platform 4.2 EL5 Redhat JBoss Enterprise Application Platform 4.2 EL4 Redhat JBoss Enterprise Application Platform 4.2 |
| Not Vulnerable: |
Sun Java Server Faces 1.2_08 Redhat JBoss Enterprise Application Platform 4.3 .CP01 Redhat JBoss Enterprise Application Platform 4.2 .CP03 |
Discussion
Sun Java Server Faces Cross-Site Scripting Vulnerability
Sun Java Server Faces is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of an affected site running an application that is based on Java Server Faces. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Sun Java Server Faces 1.2 is vulnerable; other versions may be affected as well.
Sun Java Server Faces is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of an affected site running an application that is based on Java Server Faces. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Sun Java Server Faces 1.2 is vulnerable; other versions may be affected as well.
Exploit / POC
Sun Java Server Faces Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Sun Java Server Faces Cross-Site Scripting Vulnerability
Solution:
The vendor released Sun Java Server Faces 1.2_08 to address this issue. Please see the references for more information.
Sun Java Server Faces 1.2
Solution:
The vendor released Sun Java Server Faces 1.2_08 to address this issue. Please see the references for more information.
Sun Java Server Faces 1.2
References
Sun Java Server Faces Cross-Site Scripting Vulnerability
References:
References:
- JBoss Enterprise Application Platform 4.2.0.CP03 (Red Hat)
- JBoss Enterprise Application Platform 4.3.0.CP01 (Red Hat)
- Sun Java Server Faces (Sun)
- 233561 (Sun)
- RHSA-2008:0825-10 - Moderate: JBoss Enterprise Application Platform 4.2.0.CP03 s (Red Hat)
- RHSA-2008:0826-7 - Moderate: JBoss Enterprise Application Platform 4.3.0.CP01 se (Red Hat)
- RHSA-2008:0827-6 - Moderate: JBoss Enterprise Application Platform 4.2.0.CP03 se (Red Hat)
- RHSA-2008:0828-4 - Moderate: JBoss Enterprise Application Platform 4.3.0CP01 sec (Red Hat)