Apache Brooklyn Cross Site Request Forgery and Multiple Cross Site Scripting Vulnerabilities

Apache Brooklyn is prone to a cross-site request-forgery vulnerability and multiple cross-site scripting vulnerabilities.

An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or perform unauthorized actions. Other attacks may also be possible.

Apache Brooklyn 0.9.0 and prior versions are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus