A cross-site scripting vulnerability has been discovered in iPlanet web servers. The vulnerability exists when an administrator views logs in the iPlanet Admin Server. An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied HTML and script code may be executed on a web client in the context of the Admin Server site. This may allow for theft of cookie-based authentication credentials and other attacks.
A cross-site scripting vulnerability has been discovered in iPlanet web servers. The vulnerability exists when an administrator views logs in the iPlanet Admin Server. An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied HTML and script code may be executed on a web client in the context of the Admin Server site. This may allow for theft of cookie-based authentication credentials and other attacks.