vendor:
Ws02Carbon
by:
John Page aka HYP3RLINX
6.1
CVSS
MEDIUM
Persistent / Reflected Cross Site Scripting (XSS) - Cookie Disclosure
CWE
Product Name: Ws02Carbon
Affected Version From: 4.4.2005
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2016-4316
CPE: a:wso2:ws02carbon:4.4.5
Platforms Tested:
WSO2 CARBON v4.4.5 Persistent XSS Cookie Theft
WSo2 Carbon has multiple XSS vectors allowing attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy, stealing session cookies and used as a platform for further attacks on the system.