IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:48356
Info
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 48356 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2606 CVE-2011-2607 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2011 12:00AM |
| Updated: | Apr 13 2015 09:05PM |
| Credit: | IBM |
| Vulnerable: |
IBM Rational Team Concert 3.0 |
| Not Vulnerable: | |
Discussion
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
IBM Rational Team Concert is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
IBM Rational Team Concert 3.0 is vulnerable.
IBM Rational Team Concert is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
IBM Rational Team Concert 3.0 is vulnerable.
Exploit / POC
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References: