Multiple IBM Products CVE-2014-6196 Unspecified Cross Site Scripting Vulnerability
BID:71262
Info
Multiple IBM Products CVE-2014-6196 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 71262 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6196 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2014 12:00AM |
| Updated: | Nov 19 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Dashboard Framework 8.5.0.1 IBM WebSphere Dashboard Framework 8.5 IBM WebSphere Dashboard Framework 8.0 IBM WebSphere Dashboard Framework 7.0.1 IBM WebSphere Dashboard Framework 7.0 IBM WebSphere Dashboard Framework 6.1.5 IBM Web Experience Factory 6.1.5 IBM Web Experience Factory 8.5.0.1 IBM Web Experience Factory 8.5.0.0 IBM Web Experience Factory 8.0 IBM Web Experience Factory 7.0.1 IBM Web Experience Factory 7.0 IBM Lotus Widget Factory 7.0.1 IBM Lotus Widget Factory 6.1.5 IBM Lotus Widget Factory 8.5.0.1 IBM Lotus Widget Factory 8.5 IBM Lotus Widget Factory 8.0 IBM Lotus Widget Factory 7.0 |
| Not Vulnerable: | |
Discussion
Multiple IBM Products CVE-2014-6196 Unspecified Cross Site Scripting Vulnerability
Multiple IBM Products are prone to an unspecified cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
Multiple IBM Products are prone to an unspecified cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
References
Multiple IBM Products CVE-2014-6196 Unspecified Cross Site Scripting Vulnerability
References:
References: