Record summary

CVE-2008-0240 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame InjectionExploitDB exploitby Jan Fry & Adrian PastorNot analyzed1 file
ExploitDB

PoC details

References

10