CVE-2010-2433
IBM WebSphere ILOG JRules 6.7 - Cross-Site Scripting via RTS URL to explore.jsp, compose.jsp, or home.jsp
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2433. PoCs published by IBM.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM WebSphere ILOG JRules 6.7 by injecting a script tag into the URI, which executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM WebSphere ILOG JRules 6.7 by injecting a script tag into the URI, which executes arbitrary JavaScript in the context of the affected site.