Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
BID:34155
Info
Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
| Bugtraq ID: | 34155 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1729 |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2009 12:00AM |
| Updated: | May 21 2009 04:20PM |
| Credit: | The SCS team from Core Security Technologies |
| Vulnerable: |
Sun Java System Communications Express 6.3 Sun Java System Communications Express 2005Q4 |
| Not Vulnerable: | |
Discussion
Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
Sun Java System Communications Express is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue is tracked by Sun Alert ID 258068.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The following are vulnerable:
Sun Java System Communications Express 6.3 for Sun Java Communications Suite 5 and 6
Sun Java System Communications Express 6 2005Q4 (6.2)
Sun Java System Communications Express is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue is tracked by Sun Alert ID 258068.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The following are vulnerable:
Sun Java System Communications Express 6.3 for Sun Java Communications Suite 5 and 6
Sun Java System Communications Express 6 2005Q4 (6.2)
Exploit / POC
Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
Solution / Fix
Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Sun Java System Communications Express 6.3
Solution:
The vendor has released updates. Please see the references for details.
Sun Java System Communications Express 6.3
-
Sun 122793-26
SPARC
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -122793-26-1 -
Sun 122794-26
x86
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -122794-26-1 -
Sun 122795-26
Linux
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -122795-26-1
References
Sun Java System Communications Express 'UWCMain' Cross Site Scripting Vulnerability
References:
References:
- Multiple XSS in Sun Communications Express (CORE Security Technologies)
- Sun Java System Communications Express Homepage (Sun)
- CORE-2009-0109 - Multiple XSS in Sun Communications Express (CORE Security Technologies Advisories
) - Solution 258068 : Cross-Site Scripting (XSS) Vulnerability in Sun Java System (Sun)