Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Neoteris Instant Virtual Extranet Cross Site Scripting Session Hijacking Vulnerability

Neoteris Instant Virtual Extranet (IVE) has been reported prone to a cross-site scripting vulnerability.

The issue presents itself, due to a lack of sufficient sanitization performed on an argument passed to an IVE CGI script. An attacker may exploit this vulnerability to hijack valid Neoteris IVE sessions.







 

Privacy Statement
Copyright 2008, SecurityFocus