PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
BID:9036
Info
PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9036 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0629 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Glyn Geoghegan. |
| Vulnerable: |
PeopleSoft PeopleTools 8.43 PeopleSoft PeopleTools 8.42 PeopleSoft PeopleTools 8.41 PeopleSoft PeopleTools 8.40 PeopleSoft PeopleTools 8.20 PeopleSoft PeopleTools 8.19 PeopleSoft PeopleTools 8.18 PeopleSoft PeopleTools 8.17 PeopleSoft PeopleTools 8.16 PeopleSoft PeopleTools 8.15 PeopleSoft PeopleTools 8.14 PeopleSoft PeopleTools 8.13 PeopleSoft PeopleTools 8.12 PeopleSoft PeopleTools 8.11 PeopleSoft PeopleTools 8.10 PeopleSoft PeopleTools 8.4 |
| Not Vulnerable: | |
Discussion
PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
PeopleSoft PeopleTools IScript is reported to be prone to cross-site scripting attacks. This could allow an attacker to embed hostile HTML and script code into a malicious link, that could be rendered in the web browser of a victim user if the link were visited. This could be exploited to steal cookie-based authentication credentials or to launch other attacks.
PeopleSoft PeopleTools IScript is reported to be prone to cross-site scripting attacks. This could allow an attacker to embed hostile HTML and script code into a malicious link, that could be rendered in the web browser of a victim user if the link were visited. This could be exploited to steal cookie-based authentication credentials or to launch other attacks.
Exploit / POC
PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
Solution:
PeopleSoft has released the following patches to address this issue:
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
These patches are available via the PeopleSoft Customer Connection.
Solution:
PeopleSoft has released the following patches to address this issue:
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
These patches are available via the PeopleSoft Customer Connection.
References
PeopleTools PeopleSoft IScript Cross-Site Scripting Vulnerability
References:
References:
- PeopleSoft Customer Connection (PeopleSoft)
- PeopleSoft Homepage (PeopleSoft)
- Corsaire Security Advisory: PeopleSoft IScript XSS issue ("advisories"
)