Document Title: =============== IBM Website Service - Cross Site Scripting Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=480 Release Date: ============= 2012-07-05 Vulnerability Laboratory ID (VL-ID): ==================================== 480 Common Vulnerability Scoring System: ==================================== 2 Product & Service Introduction: =============================== http://www.almaden.ibm.com/ Abstract Advisory Information: ============================== A Vulnerability Laboratory Researcher discovered multiple non persistent Cross Site Scripting Vulnerabilities on IBMs Almaden Service. Vulnerability Disclosure Timeline: ================================== 2012-07-06: Public or Non-Public Disclosure Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ Multiple client side cross site scripting vulnerabilities are detected on IBMs Almaden Service. The vulnerability allows an attacker (remote) to hijack customer/moderator/admin sessions with medium required user inter action. Successful exploitation can result in account steal or client side context manipulation when processing affected module application requests. Vulnerable Module(s): [+] event_details.cgi? Proof of Concept (PoC): ======================= The vulnerabilities cna be exploited by remote attacker with medium required user inter aciton. For demonstration or reproduce ... http://www.almaden.ibm.com/cgi-bin/cs/event_details.cgi?uid=AB0503BF4D2DAC02882579C000608B40 &topic='"-->