Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-0240

Severity
4.3MEDIUM
EPSS
7.4%
top 8.28%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 11
Latest updateMay 1

Description

/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cr98-r54j-j39h: /idm/help/index2022-05-01
CVEList
CVE-2008-0240: /idm/help/index2008-01-11

💥Exploits & PoCs

1
Exploit-DB
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection2008-01-09