4.3
CVSSv2

CVE-2008-0240

Published: 11/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote malicious users to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

Vulnerable Product Search on Vulmon Subscribe to Product

sun java system identity manager 7.1

sun java system identity manager 6.0

sun java system identity manager 7.0

Exploits

source: wwwsecurityfocuscom/bid/27214/info Sun Java System Identity Manager is prone to multiple input-validation vulnerabilities, including an HTML-injection issue and cross-site scripting issues, because it fails to adequately sanitize user-supplied input Attackers can exploit these issues to execute arbitrary HTML and script code ...