PeopleSoft PeopleTools JMS Listening Connector Activity Parameter XSS

This script is Copyright (C) 2009-2012 Tenable Network Security, Inc.


Synopsis :

The remote web server hosts an application that is prone to a
cross-site scripting attack.

Description :

The remote web server is running an instance of PeopleSoft PeopleTools
that fails to sanitize user-supplied input to the 'Activity' parameter
on submission to the JMS Listening Connector Administrator interface
before using it to generate dynamic HTML output. An attacker may be
able to leverage this to inject arbitrary HTML and script code into a
user's browser to be executed within the security context of the
affected site.

See also :

http://www.nessus.org/u?e1e87349

Solution :

Upgrade to version 8.49.22 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.2
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: CGI abuses : XSS

Nessus Plugin ID: 42352 ()

Bugtraq ID: 35691

CVE ID: CVE-2009-1987