Cross-Site Scripting Vulnerability in Sun Java System Communications Express
CVE-2010-1227

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
1 April 2010

What is CVE-2010-1227?

A cross-site scripting (XSS) vulnerability exists in Sun Java System Communications Express versions 6.2 and 6.3. This flaw enables remote attackers to inject arbitrary web scripts or HTML through the subject field of a message. The exploit can lead to serious security implications, as demonstrated when an attacker includes an IMG element with a SRC attribute leading to cross-site request forgery (CSRF) attacks using the cmd and argv parameters to cmd.msc. Organizations using affected versions should implement necessary security patches to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.