|
Microsoft Content Management Server Cross-Site Scripting Vulnerability
A vulnerability has been discovered in Microsoft Content Mangement Server (MCMS). Due to insufficient sanitization of user-supplied input MCMS may be prone to cross site scripting attacks. The issue occurs when constructing a response page which relies on various user-supplied values. By constructing a malicious link an attacker may be able to trick an unsuspecting user into triggering this vulnerability. This could be used to steal a user's private information, such as cookie-based authentication credentials. Other attacks are also possible. This issue may be the same vulnerability described in BID 5922. |
|
|
Privacy Statement |