Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Content Management Server Cross-Site Scripting Vulnerability

A vulnerability has been discovered in Microsoft Content Mangement Server (MCMS). Due to insufficient sanitization of user-supplied input MCMS may be prone to cross site scripting attacks. The issue occurs when constructing a response page which relies on various user-supplied values.

By constructing a malicious link an attacker may be able to trick an unsuspecting user into triggering this vulnerability. This could be used to steal a user's private information, such as cookie-based authentication credentials. Other attacks are also possible.

This issue may be the same vulnerability described in BID 5922.







 

Privacy Statement
Copyright 2008, SecurityFocus