BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
BID:47324
Info
BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
| Bugtraq ID: | 47324 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0286 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2011 12:00AM |
| Updated: | Apr 13 2011 03:34PM |
| Credit: | Ivan Huertas of Cybsec. |
| Vulnerable: |
Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 |
| Not Vulnerable: | |
Discussion
BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
The Web Desktop Manager component of BlackBerry Enterprise Server is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
The Web Desktop Manager component of BlackBerry Enterprise Server is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Exploit / POC
BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Solution:
The vendor has released an advisory and updates. Please see the references for details.
References
BlackBerry Enterprise Server Web Desktop Manager Component Cross Site Scripting Vulnerability
References:
References:
- CYBSEC Advisory 2011 0401 Cross-Site Scripting (XSS) in Blackberry WebDesktop (CYBSEC Labs)
- Research In Motion Homepage (Research In Motion)
- Cross-site scripting (XSS) vulnerability in the BlackBerry Web Desktop Manager c (Research In Motion)