HTTP: IPlanet Admin Server Tool XSS Execution
This signature detects attempts to exploit a known vulnerability in iPlanet Web server. iPlanet 4.x SP11 and earlier versions are vulnerable. The iPlanet log viewer contains a cross site scripting vulnerability. Attackers can embed maliciously crafted JavaScript code inside a URL request; when the iPlanet administrator opens the Admin Server Tool to browse Web logs, attackers can use the embedded code to execute arbitrary commands.
Extended Description
A cross-site scripting vulnerability has been discovered in iPlanet web servers. The vulnerability exists when an administrator views logs in the iPlanet Admin Server. An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link. Attacker-supplied HTML and script code may be executed on a web client in the context of the Admin Server site. This may allow for theft of cookie-based authentication credentials and other attacks.
Affected Products
Sun iplanet_web_server_enterprise_edition
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Sun
6.8