Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sun Java System Identity Manager 多个输入验证漏洞
Vulnerability Description
Sun Java System Communications Express为Sun Java通讯套件提供了WEB客户端,允许通过浏览器管理邮件、日历、任务等。 Sun Java System Identity Manager 6.0 SP1到SP3,7.0以及7.1版本中的多个跨站脚本漏洞允许远程攻击者通过3种途径来注入任意的HTML或者Web脚本:(1)对/idm/login.jsp的cntry或者lang参数,(2)对/idm/account/findForSelect.jsp的结果形式参数,或者(
CVSS Information
N/A
Vulnerability Type
N/A