IBM Tivoli Monitoring Eclipse Help Server Cross-Site Scripting and Spoofing Vulnerabilities
BID:49891
Info
IBM Tivoli Monitoring Eclipse Help Server Cross-Site Scripting and Spoofing Vulnerabilities
| Bugtraq ID: | 49891 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2011 12:00AM |
| Updated: | Sep 30 2011 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 IBM Tivoli Monitoring 6.2 |
| Not Vulnerable: |
IBM Tivoli Monitoring 6.2.2 FP6 |
Discussion
IBM Tivoli Monitoring Eclipse Help Server Cross-Site Scripting and Spoofing Vulnerabilities
IBM Tivoli Monitoring Eclipse Help Server is prone to a cross-site scripting vulnerability and a vulnerability that may aid in phishing attacks.
An attacker may leverage these issues to mislead a user to believe that they are viewing a legitimate site, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or steal cookie-based authentication credentials. Other attacks are also possible.
IBM Tivoli Monitoring Eclipse Help Server is prone to a cross-site scripting vulnerability and a vulnerability that may aid in phishing attacks.
An attacker may leverage these issues to mislead a user to believe that they are viewing a legitimate site, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or steal cookie-based authentication credentials. Other attacks are also possible.