CVE-2010-0714
published 2010-02-26CVE-2010-0714: Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
3.53%
87.9th percentile
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.
Affected
77 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_quickr | — | — |
| ibm | lotus_quickr | — | — |
| ibm | lotus_quickr | — | — |
| ibm | lotus_quickr | — | — |
| ibm | lotus_quickr | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
| ibm | lotus_web_content_management | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Exchange Server 2000 - XEXCH50 Heap Overflow (MS03-046) (Metasploit)
exploitdb·2010-11-11
CVE-2003-0714 Microsoft Exchange Server 2000 - XEXCH50 Heap Overflow (MS03-046) (Metasploit)
Microsoft Exchange Server 2000 - XEXCH50 Heap Overflow (MS03-046) (Metasploit)
---
##
# $Id: ms03_046_exchange2000_xexch50.rb 10998 2010-11-11 22:43:22Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'MS03-046 Exchange 2000 XEXCH50 Heap Overflow',
'Description' => %q{
This is an exploit for the Exchange 2000 heap overflow. Due
to the nature of the vulnerability, this exploit is not very
reliable. This module has been tested against Exchange 2000
SP0 and SP3 running a Windows 2000 system patched to SP4. It
normally takes between one
Exploit-DB
IBM (Multiple Products) - Login Page Cross-Site Scripting
exploitdb·2010-02-25
CVE-2010-0714 IBM (Multiple Products) - Login Page Cross-Site Scripting
IBM (Multiple Products) - Login Page Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/38412/info
Multiple IBM products are prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue affects IBM Lotus Web Content Management, WebSphere Portal, and Lotus Quickr.
http://www.example.com/wps/wcm/webinterface/login/login.jsp?";>maliciou s_script<b%20"
http://www.example.com/wps/wcm/webinterface/login/login.jsp?"; style="tr:expression(malicious_script)
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21421469http://www-1.ibm.com/support/docview.wss?uid=swg1PM03233http://www.hacktics.com/content/advisories/AdvIBM20100224.htmlhttp://www.securityfocus.com/archive/1/509744/100/0/threadedhttp://www.securityfocus.com/bid/38412http://www.securitytracker.com/id?1023660https://exchange.xforce.ibmcloud.com/vulnerabilities/56508http://www-01.ibm.com/support/docview.wss?uid=swg21421469http://www-1.ibm.com/support/docview.wss?uid=swg1PM03233http://www.hacktics.com/content/advisories/AdvIBM20100224.htmlhttp://www.securityfocus.com/archive/1/509744/100/0/threadedhttp://www.securityfocus.com/bid/38412http://www.securitytracker.com/id?1023660https://exchange.xforce.ibmcloud.com/vulnerabilities/56508
2010-02-26
Published