Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

IBM WebSphere Application Server UDDI Console Multiple Input Validation Vulnerabilities

WebSphere Application Server is prone to multiple cross-site request-forgery and cross-site scripting vulnerabilities.

Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary script code, and use a victim's currently active session to perform actions with the application.

WebSphere Application Server 6.0 and 6.1 are vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus