11 lines
No EOL
723 B
Text
11 lines
No EOL
723 B
Text
source: https://www.securityfocus.com/bid/6000/info
|
|
|
|
A vulnerability has been discoverered in the Caching Proxy component bundled with the IBM Websphere Edge Server.
|
|
|
|
It has been reported that the Caching Proxy is vulnerable to cross site scripting attacks. Due to insufficient sanitization of user-supplied input it is possible for an attacker to construct a malicious link which contains arbitrary HTML and script code, which will be executed in the web client of a user who visits the malicious link.
|
|
|
|
Attacks of this nature may make it possible for attackers to steal cookie-based authentication credentials.
|
|
|
|
Request the following path from the caching proxy server:
|
|
|
|
/"><img%20src="javascript:alert(document.domain)"> |