Tmax Soft JEUS 3.1.4 p1 - URL.jsp Cross-Site Scripting

EDB-ID:

22805

CVE:





Platform:

JSP

Date:

2003-06-17


source: https://www.securityfocus.com/bid/7969/info

Reportedly, Tmax Soft JEUS is vulnerable to a cross site-scripting attack. The vulnerability is present in the url.jsp script of the Tmax Soft JEUS server.

An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link.

It should be noted that although this vulnerability has been reported to affect Tmax Soft JEUS version 3.1.4p1, all version prior to release 3.2.2 are also reported vulnerable.

http://www.example.com/url.jsp?foo=<script>alert('XSS vulnerability exists!')</script>