CVE-2008-0240
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites...
- 公開済み
- 2008/01/11
- 更新済み
- 2024/08/07
- CNA の割り当て
- mitre
- 観察された証拠
- 2008/01/09
プライマリ CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N低 · 今後 30 日間
- パーセンタイル
- 92.9%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection." Sun Java System Identity Manager 6.0 SP1~SP3、7.0、および7.1の/idm/help/index.jspは、リモートの攻撃者が任意のWebサイトからフレームを注入し、helpUrlパラメータを介してフィッシング攻撃を実行することを可能にします。別名「frame injection(フレーム注入)」とも呼ばれます。
ソース
1- Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injectionエクスプロイト
Jan Fry & Adrian Pastor · jsp · 2008/01/09
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。