Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.
References 7 Total
- rhn.redhat.com: RHSA-2013:1862 vendor-advisory
- securityfocus.com: 62659 vdb-entry
- http://fusesource.com/issues/browse/FMC-495
- rhn.redhat.com: RHSA-2013:1286 vendor-advisory
- http://fusesource.com/forge/git/fuseenterprise.git/?p=fuseenterprise.git%3Ba=commitdiff%3Bh=f5436ea1c5547c851bb6f92561272fe42c146e68
- https://bugzilla.redhat.com/show_bug.cgi?id=1011736
- https://github.com/jboss-fuse/fuse/commit/e280cb370323eeb759030919d5111ed809e8ded5
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- rhn.redhat.com: RHSA-2013:1862 vendor-advisoryx_transferred
- securityfocus.com: 62659 vdb-entryx_transferred
- http://fusesource.com/issues/browse/FMC-495 x_transferred
- rhn.redhat.com: RHSA-2013:1286 vendor-advisoryx_transferred
- http://fusesource.com/forge/git/fuseenterprise.git/?p=fuseenterprise.git%3Ba=commitdiff%3Bh=f5436ea1c5547c851bb6f92561272fe42c146e68 x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=1011736 x_transferred
- https://github.com/jboss-fuse/fuse/commit/e280cb370323eeb759030919d5111ed809e8ded5 x_transferred