vendor:
BlackBerry Enterprise Server MDS Connection Service
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: BlackBerry Enterprise Server MDS Connection Service
Affected Version From: Prior to BlackBerry Enterprise Server 4.1.6 MR5
Affected Version To: BlackBerry Enterprise Server 4.1.6 MR5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
BlackBerry Enterprise Server MDS Connection Service Cross-Site Scripting Vulnerability
BlackBerry Enterprise Server MDS Connection Service is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Mitigation:
Input validation should be used to ensure that untrusted data is not used to generate unexpected results in the application.