Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: CGI abuses : XSS --> Category: infos

Sun Secure Global Desktop / Tarantella < 4.20.983 Cross-Site Scripting Vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
Checks version of Sun Secure Global Desktop / Tarantella

Detailed Explanation for this Vulnerability Test

Synopsis :

The remote web server contains CGI scripts that are vulnerable to
cross-site scripting attacks.

Description :

Sun Secure Global Desktop or Tarantella, a Java-based program for
web-enabling applications running on a variety of platforms, is
installed on the remote web server.

According to the version reported in one of its scripts, the
installation of the software on the remote host fails to sanitize
user-supplied input to several unspecified parameters before using it
to generate dynamic web content. An unauthenticated remote attacker
may be able to leverage these issues to inject arbitrary HTML and
script code into a user's browser to be evaluated within the security
context of the affected web site.

See also :

http://www.securityfocus.com/archive/1/446566/30/0/threaded
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102650-1

Solution :

Upgrade to Sun Secure Global Desktop version 4.20.983 or later.

Threat Level:

High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.