CVE Database
/

CVE-2008-0239

Back to search

CVE-2008-0239

Published: Jan 11, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.

VendorProductVersions

n/a

n/a

affected
n/a

References

103180
vendor-advisory
x_refsource_SUNALERT
ADV-2008-0089
vdb-entry
x_refsource_VUPEN
28356
third-party-advisory
x_refsource_SECUNIA
3535
third-party-advisory
x_refsource_SREASON
1019175
vdb-entry
x_refsource_SECTRACK
sun-identity-lang-xss(39581)
vdb-entry
x_refsource_XF
200558
vendor-advisory
x_refsource_SUNALERT
sun-identity-main-xss(39583)
vdb-entry
x_refsource_XF
sun-identity-login-xss(39580)
vdb-entry
x_refsource_XF
27214
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now