Summary
Sun Solaris AnswerBook2 is reported prone to multiple cross-site scripting vulnerabilities. These issues arise due to insufficient sanitization of user-supplied data facilitating execution of arbitrary HTML and script code in a user's browser.
The following specific issues were identified:
It is reported that the Search function of the application is affected by a cross-site scripting vulnerability.
The AnswerBook2 admin interface is prone to cross-site scripting attacks as well.
These issues can lead to theft of cookie based credentials and other attacks.
AnswerBook2 1.4.4 and prior versions are affected by these issues.
Solution
Sun has released a advisory to address these issues. The vendor recommends disabling the application and referring to Sun documentation at the Sun Product Documentation Web site at http://docs.sun.com or viewing the documentation on the Solaris Documentation CD.
Please see the referenced advisory for more information.
References
Severity
Classification
-
CVE CVE-2005-0548, CVE-2005-0549 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- 2532|Gigs Directory Traversal And SQL Injection Multiple Vulnerabilities
- Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
- Aardvark Topsites <= 4.2.2 Remote File Inclusion Vulnerability
- Annuaire PHP 'sites_inscription.php' Cross Site Scripting Vulnerability
- Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability