Sun Secure Global Desktop / Tarantella < 4.20.983 Multiple XSS

This script is Copyright (C) 2006-2014 Tenable Network Security, Inc.


Synopsis :

The remote web server contains CGI scripts that are vulnerable to
cross-site scripting attacks.

Description :

Sun Secure Global Desktop or Tarantella, a Java-based program for
web-enabling applications running on a variety of platforms, is
installed on the remote web server.

According to the version reported in one of its scripts, the
installation of the software on the remote host fails to sanitize
user-supplied input to several unspecified parameters before using it
to generate dynamic web content. An unauthenticated, remote attacker
may be able to leverage these issues to inject arbitrary HTML and
script code into a user's browser to be evaluated within the security
context of the affected website.

See also :

http://www.securityfocus.com/archive/1/446566/30/0/threaded
http://www.nessus.org/u?1d074268

Solution :

Upgrade to Sun Secure Global Desktop version 4.20.983 or later.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.5
(CVSS2#E:F/RL:U/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 22495 ()

Bugtraq ID: 20135
20276

CVE ID: CVE-2006-4958
CVE-2006-4959