CVE-2010-0714 Information

Description

Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal IBM Lotus Web Content Management (WCM) and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5 6.0.0.0 through 6.0.0.4 6.0.1.0 through 6.0.1.7 6.1.0.0 through 6.1.0.3 and 6.1.5.0; and IBM Lotus Quickr services 8.0 8.0.0.2 8.1 8.1.1 and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.

Reference

http://www.hacktics.com/content/advisories/AdvIBM20100224.html http://www.securityfocus.com/archive/1/509744/100/0/threaded http://www.securityfocus.com/bid/38412 http://www.securitytracker.com/id?1023660 http://www-01.ibm.com/support/docview.wss?uid=swg21421469 http://www-1.ibm.com/support/docview.wss?uid=swg1PM03233 https://exchange.xforce.ibmcloud.com/vulnerabilities/56508

Share on: