IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
BID:47954
Info
IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 47954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2172 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2011 12:00AM |
| Updated: | Mar 22 2012 08:50PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Portal 6.1.5 .0 IBM Websphere Portal 7.0.0.1 IBM Web Content Management 7.0.0.1 |
| Not Vulnerable: |
IBM Websphere Portal 7.0.0.1 CF004 IBM Web Content Management 7.0.0.1 CF004 |
Discussion
IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
IBM WebSphere Portal is prone to a cross-site scripting vulnerability because it fails to properly sanitize unspecified user-supplied input to the search center.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials.
IBM WebSphere Portal is prone to a cross-site scripting vulnerability because it fails to properly sanitize unspecified user-supplied input to the search center.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials.
Exploit / POC
IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to follow a malicious URI.
To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
IBM WebSphere Portal Search Center Unspecified Cross Site Scripting Vulnerability
References:
References: