CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / february, 2005 / Jakarta Lucene Results.jsp cross-site scripting vulnerability 

Jakarta Lucene Results.jsp cross-site scripting vulnerabilit

Jakarta Lucene Results.jsp cross-site scripting vulnerabilit

Date Discovered: December 3, 2004
Date Published: February 1, 2005
Last Updated: February 1, 2005

Vulnerability Description

Vulnerability ID:          32124
Discovered by:            vendor
Exploitable Locally:     No
Exploitable Remotely: Yes
Impact:                        Remote attackers can execute arbitrary code.
Root Cause:                 Software Vulnerability

Jakarta Lucene contains a vulnerability that can allow a remote attacker to launch cross-site scripting attacks. The vulnerability is due to insufficient filtering of user-supplied data passed to the Results.jsp. Remote attackers can exploit this vulnerability to execute arbitrary HTML code.

 

 

More information on CA Vulnerability Information Center
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32124

Computer Associates – the Trusted Source of Security Knowledge

 

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel