First published: Sun Mar 09 2008(Updated: )
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Quickr Server | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1216 allows remote attackers to inject arbitrary web script or HTML into affected IBM Lotus Quickr servers.
You can mitigate CVE-2008-1216 by applying available security patches or updates provided by IBM for Lotus Quickr 8.0.
CVE-2008-1216 affects IBM Lotus Quickr Server 8.0 and possibly QuickPlace 7.x.
CVE-2008-1216 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2008-1216 has known exploit techniques that utilize the Calendar OpenDocument action to manipulate URIs.