Quest ActiveRoles Server Multiple Cross Site Scripting Vulnerabilities
BID:52965
Info
Quest ActiveRoles Server Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 52965 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2012 12:00AM |
| Updated: | Apr 10 2012 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Quest Software ActiveRoles Server 6.7 |
| Not Vulnerable: |
Quest Software ActiveRoles Server 6.7.0 Patch 4 Build |
Discussion
Quest ActiveRoles Server Multiple Cross Site Scripting Vulnerabilities
ActiveRoles Server is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to ActiveRoles Server 6.7.0 Patch 4 Build 3694 are vulnerable.
ActiveRoles Server is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to ActiveRoles Server 6.7.0 Patch 4 Build 3694 are vulnerable.
References
Quest ActiveRoles Server Multiple Cross Site Scripting Vulnerabilities
References:
References:
- ActiveRoles Server 6.7.0 Generic Patch 4 (Build 3694) (Quest Software)
- ActiveRoles Server Homepage (Quest Software)