Vulnerabilities > CVE-2007-0110 - Cross-Site Scripting vulnerability in Novell Access Manager Identity Server 3

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
novell
exploit available

Summary

Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.

Vulnerable Configurations

Part Description Count
Application
Novell
2

Exploit-Db

descriptionNovell Access Manager 3 Identity Server IssueInstant Parameter Cross-Site Scripting Vulnerability. CVE-2007-0110. Remote exploit for novell platform
idEDB-ID:29400
last seen2016-02-03
modified2007-01-08
published2007-01-08
reporteranonymous
sourcehttps://www.exploit-db.com/download/29400/
titleNovell Access Manager 3 Identity Server IssueInstant Parameter Cross-Site Scripting Vulnerability