Cross Site Scripting Vulnerability in IBM Tivoli Directory Server 4.1
A cross-site scripting vulnerability exists in the IBM Tivoli Directory Server Web Admin GUI.
Ken Pfeil
December 3, 2003
1 Min Read
Reported December 3, 2003, by Oliver Karow.
VERSIONS AFFECTED
IBM Tivoli Directory Server 4.1
DESCRIPTION
A cross-site scripting vulnerability exists in the IBM Tivoli Directory Server Web Admin GUI. By sending a URL such as https://server/ldap/cgi-bin/ldacgi.exe?Action=, an attacker can insert arbitrary HTML and JavaScript code into the IBM Tivoli Directory Server Admin Web page.
VENDOR RESPONSE
IBM has been notified.
CREDIT
Discovered byOliver Karow.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like