4.3
CVSSv2

CVE-2008-0239

Published: 11/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote malicious users to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

sun java system identity manager 6.0

sun java system identity manager 7.0

sun java system identity manager 7.1

Exploits

source: wwwsecurityfocuscom/bid/27214/info Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input Attackers can exploit these issues to execute arbitrary HTML and script code in ...
source: wwwsecurityfocuscom/bid/27214/info Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input Attackers can exploit these issues to execute arbitrary HTML and script code i ...
source: wwwsecurityfocuscom/bid/27214/info Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input Attackers can exploit these issues to execute arbitrary HTML and script co ...