VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2103
axis2: Cross-site scripting (XSS) vulnerability in axis2-a...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2103

Original

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-27
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-28




Affected Product Tags
cpe:/a:3com:intelligent_management_center
cpe:/a:apache:axis2:1.4.1
cpe:/a:apache:axis2:1.5.1
cpe:/a:sap:business_objects:12
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
BID 40327




BUGTRAQ 20100521 PR10-03: Authenticated Cross-Site Scripting (XSS) within the Apache Axis2 administration console




MISC http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-03




MISC http://www.exploit-db.com/exploits/12689




OSVDB 64844




SECUNIA 39906




VUPEN ADV-2010-1215




Vulnerability Type Cross-Site Scripting (XSS) (CWE-79)




XF axis2-modules-xss(58790)





Copyright © 2010 JPCERT/CC All Rights Reserved.