CVE-2008-1216: Input Validation
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2008-1216?
CVE-2008-1216 allows remote attackers to inject arbitrary web script or HTML into affected IBM Lotus Quickr servers.
How can I mitigate CVE-2008-1216?
You can mitigate CVE-2008-1216 by applying available security patches or updates provided by IBM for Lotus Quickr 8.0.
Which versions are affected by CVE-2008-1216?
CVE-2008-1216 affects IBM Lotus Quickr Server 8.0 and possibly QuickPlace 7.x.
What type of vulnerability is CVE-2008-1216?
CVE-2008-1216 is classified as a cross-site scripting (XSS) vulnerability.
Is there a known exploit for CVE-2008-1216?
Yes, CVE-2008-1216 has known exploit techniques that utilize the Calendar OpenDocument action to manipulate URIs.