Cross Site Scripting Vulnerability in IBM Tivoli Directory Server 4.1

A cross-site scripting vulnerability exists in the IBM Tivoli Directory Server Web Admin GUI.

Ken Pfeil

December 3, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported December 3, 2003, by Oliver Karow.

 

 

VERSIONS AFFECTED

 

  • IBM Tivoli Directory Server 4.1

 

DESCRIPTION

 

A cross-site scripting vulnerability exists in the IBM Tivoli Directory Server Web Admin GUI. By sending a URL such as https://server/ldap/cgi-bin/ldacgi.exe?Action=, an attacker can insert arbitrary HTML and JavaScript code into the IBM Tivoli Directory Server Admin Web page.

 

VENDOR RESPONSE

 

IBM has been notified.

 

CREDIT

 

Discovered byOliver Karow.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like