IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
BID:68212
Info
IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
| Bugtraq ID: | 68212 |
| Class: | Design Error |
| CVE: |
CVE-2013-6309 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2014 12:00AM |
| Updated: | Jun 19 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Marketing Platform 9.1 |
| Not Vulnerable: |
IBM Marketing Platform 9.1.0.2 |
Discussion
IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
IBM Marketing Platform is prone to a link injection vulnerability.
Attackers can exploit this issue to inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages.
IBM Marketing Platform 9.1 is vulnerable.
IBM Marketing Platform is prone to a link injection vulnerability.
Attackers can exploit this issue to inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages.
IBM Marketing Platform 9.1 is vulnerable.
Exploit / POC
IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Marketing Platform CVE-2013-6309 Link Injection Vulnerability
References:
References: