CVE-2008-0240
Sun Java System Identity Manager 6.0 SP1-SP3, 7.0, 7.1 - Frame Injection via helpUrl Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0240. PoCs published by Jan Fry & Adrian Pastor.
AI-analyzed exploit summary The provided text describes an HTML injection and XSS vulnerability in Sun Java System Identity Manager due to inadequate input sanitization. It includes a proof-of-concept URL demonstrating the issue but lacks executable exploit code.
Description
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Exploits (1)
The provided text describes an HTML injection and XSS vulnerability in Sun Java System Identity Manager due to inadequate input sanitization. It includes a proof-of-concept URL demonstrating the issue but lacks executable exploit code.