CVE-2008-0240
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."
- Affected products
- Sun Java System Identity Manager
- Sun Java System Identity Manager
- = 6.0, 7.0, 7.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 5.8% (92th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2008-01-11
CVE-2008-0240 at NVD
1 known exploit for CVE-2008-0240
Proof-of-concept code and exploit modules indexed by Sploitus