CVE-2010-1227: XSS
Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF) attack involving the cmd and argv parameters to cmd.msc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1227?
The severity of CVE-2010-1227 is classified as medium due to the potential for exploitation via cross-site scripting.
How do I fix CVE-2010-1227?
To fix CVE-2010-1227, consider upgrading to a patched version of Sun Java System Communications Express.
What versions are affected by CVE-2010-1227?
CVE-2010-1227 affects Sun Java System Communications Express versions 6.2 and 6.3.
Can CVE-2010-1227 be exploited remotely?
Yes, CVE-2010-1227 can be exploited remotely by attackers through crafted message subjects.
What kind of attack can CVE-2010-1227 facilitate?
CVE-2010-1227 can facilitate cross-site scripting (XSS) attacks by allowing injection of arbitrary web scripts.