Cross-Site Scripting Vulnerability in Sun Java System Communications Express
CVE-2010-1227
Currently unrated
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 1 April 2010
What is CVE-2010-1227?
A cross-site scripting (XSS) vulnerability exists in Sun Java System Communications Express versions 6.2 and 6.3. This flaw enables remote attackers to inject arbitrary web scripts or HTML through the subject field of a message. The exploit can lead to serious security implications, as demonstrated when an attacker includes an IMG element with a SRC attribute leading to cross-site request forgery (CSRF) attacks using the cmd and argv parameters to cmd.msc. Organizations using affected versions should implement necessary security patches to mitigate risks associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved