IBM WebSphere Cross-Site Scripting Vulnerability
BID:2969
Info
IBM WebSphere Cross-Site Scripting Vulnerability
| Bugtraq ID: | 2969 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0824 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq by "TAKAGI, Hiromitsu" <[email protected]> on July 2nd, 2001. |
| Vulnerable: |
IBM Websphere Application Server 3.5 IBM Websphere Application Server 3.0.2 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Cross-Site Scripting Vulnerability
IBM WebSphere is a series of commercial webserver and webserver related products.
IBM WebSphere does not filter script embedding from user-submitted links that are displayed on the server's websites. A malicious webmaster can exploit this vulnerability to cause JavaScript commands or embedded scripts to be executed by any user who clicks on the hyper-link.
When the malicious hyper-link is clicked it will produce the standard error message for the webserver, but it will also run the arbitrary code in the same browser as the domain.
IBM WebSphere is a series of commercial webserver and webserver related products.
IBM WebSphere does not filter script embedding from user-submitted links that are displayed on the server's websites. A malicious webmaster can exploit this vulnerability to cause JavaScript commands or embedded scripts to be executed by any user who clicks on the hyper-link.
When the malicious hyper-link is clicked it will produce the standard error message for the webserver, but it will also run the arbitrary code in the same browser as the domain.
Solution / Fix
IBM WebSphere Cross-Site Scripting Vulnerability
Solution:
The vendor has provided fix for this issue.
IBM Websphere Application Server 3.0.2
IBM Websphere Application Server 3.5
Solution:
The vendor has provided fix for this issue.
IBM Websphere Application Server 3.0.2
-
IBM WebSphere Application Server FixPack 4 (V3.02.4)
http://www-4.ibm.com/software/webservers/appserv/efix.html
IBM Websphere Application Server 3.5
-
IBM WebSphere Application Server FixPack 4 (V3.5.4)
http://www-4.ibm.com/software/webservers/appserv/efix.html