Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
BID:34083
Info
Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 34083 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1227 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2009 12:00AM |
| Updated: | Jan 18 2011 08:42PM |
| Credit: | Edgard Chammas |
| Vulnerable: |
Sun Java System Communications Express 6.3 Sun Java System Communications Express 6.2 Sun Java System Communications Express 0 |
| Not Vulnerable: | |
Discussion
Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
Sun Java System Communications Express is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
We don't know which versions of Java System Communications Express are affected. We will update this BID when more details emerge.
Sun Java System Communications Express is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
We don't know which versions of Java System Communications Express are affected. We will update this BID when more details emerge.
Exploit / POC
Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example data is available:
Attackers can use a browser to exploit these issues.
The following example data is available:
Solution / Fix
Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Sun Java System Communications Express Multiple HTML Injection Vulnerabilities
References:
References: