Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/27013 - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2007-75/advisory - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/26221 - | |
References | () http://www.securitytracker.com/id?1018868 - | |
References | () http://www.vupen.com/english/advisories/2007/3635 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38125 - |
Information
Published : 2007-10-30 19:46
Updated : 2024-11-21 00:35
NVD link : CVE-2007-4348
Mitre link : CVE-2007-4348
CVE.ORG link : CVE-2007-4348
JSON object : View
Products Affected
ibm
- tivoli_storage_manager_client
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')