PT-2008-2335 · Ibm · Ibm Websphere Edge Server Caching Proxy
Publicado
2008-02-12
·
Atualizado
2011-03-08
·
CVE-2008-0717
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Edge Server Caching Proxy (CP) versions 5.1 through 6.1
Description
A cross-site scripting (XSS) issue exists when CGI mapping rules are enabled, allowing remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.
Recommendations
For versions 5.1 through 6.1, consider disabling CGI mapping rules as a temporary workaround until a patch is available. Restrict access to error responses to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Edge Server Caching Proxy