28356Third-party advisory
http://secunia.com/advisories/28356 CVE-2008-0240
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection
Record summary
CVE-2008-0240 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame InjectionExploitDB exploitby Jan Fry & Adrian PastorNot analyzed1 file
References
103535Third-party advisory
http://securityreason.com/securityalert/3535 103180Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1 200558Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1 procheckup.com
http://www.procheckup.com/Vulnerability_PR07-10.php 20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Managermailing list
http://www.securityfocus.com/archive/1/486076/100/0/threaded 27214vdb entry
http://www.securityfocus.com/bid/27214 ADV-2008-0089vdb entry
http://www.vupen.com/english/advisories/2008/0089 sun-identity-index-frame-injection(39586)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39586 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0240