IBM Websphere Cross-Site Scripting...

- AV AC AU C I A
发布: 2001-02-02
修订: 2025-04-13

IBM Websphere is prone to a cross-site scripting vulnerability. IBM Websphere, under some circumstances, does not filter script code from URL parameters. This may enable an attacker to create a malicious link which contains arbitrary script code. The malicious link must contain a single dot-dot-slash (../) sequence, followed by the arbitrary script code. For example: http://websphereserver/../<script>alert('helloworld')</script>

0%
暂无可用Exp或PoC
当前有0条受影响产品信息