This application requires Javascript for optimal performance.

Symantec.IM.Manager.Multiple.XSS

Release Date

Oct 21, 2011

Severity

medium

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Description

This indicates an attack attempt against a Cross Site Scripting Vulnerability in Symantec IM Manager.

The vulnerability is caused due to improperly sanitized input of URL parameters to various pages of the management console. It allows a remote attacker to exploit these vulnerabilities by enticing a user to follow a specially crafted link to the management console.

Affected Products

Symantec IM Manager prior to 8.4.18

Recommended Actions

Refer to the vendor's website for suggested workaround.
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=
security_advisory&pvid=security_advisory&year=2011&suid=20110929_00

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-0552

Reference/s

http://www.securityfocus.com/bid/49739 (BugTraq)

Reference: VID-29517