PT-2008-2802 · Xitex · Xitex Webcontent M1
Published
2008-03-08
·
Updated
2017-08-08
·
CVE-2008-1209
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Xitex WebContent M1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the
sid parameter in the "redirect.do" endpoint.Recommendations
For Xitex WebContent M1, avoid using the
sid parameter in the redirect.do endpoint until a fix is available. Consider restricting access to the redirect.do endpoint to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xitex Webcontent M1