CVE-2007-4592

IBM Rational ClearQuest <2003.06.16 Patch 2008A-7.0.1.1_iFix01 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.

Exploits (1)

exploitdb WORKING POC VERIFIED
by sasquatch · textwebappsjava
https://www.exploit-db.com/exploits/31438

Scores

EPSS 0.1623
EPSS Percentile 94.7%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

ibm/rational_clearquest < 2003-06-16
ibm/rational_clearquest
ibm/rational_clearquest
ibm/rational_clearquest

Timeline

Published Mar 20, 2008
Tracked Since Feb 18, 2026