vendor:
BMC Dashboards
by:
Unknown
7.5
CVSS
HIGH
Information Disclosure, Cross-Site Scripting (XSS)
79
CWE
Product Name: BMC Dashboards
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
2010
BMC Dashboards Multiple Information Disclosure and Cross-Site Scripting Issues
BMC Dashboards is prone to multiple information-disclosure and cross-site scripting issues because the application fails to properly sanitize user-supplied input. A remote attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Exploiting the information-disclosure issues allows the attacker to view local files within the context of the webserver process.
Mitigation:
Apply necessary input validation and sanitization techniques to prevent cross-site scripting and information disclosure vulnerabilities. Regularly update the BMC Dashboards application to the latest version.