vendor:
Oracle Siebel
by:
Lament
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Oracle Siebel
Affected Version From: 7.7
Affected Version To: 7.8
Patch Exists: NO
Related CWE: Unknown
CPE: a:oracle:siebel:7.7
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerability in Oracle Siebel
An attacker can execute arbitrary script code in the browser of an unsuspecting user by injecting malicious code through user-supplied input. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
Oracle Siebel should properly sanitize user-supplied input to prevent cross-site scripting attacks.