MEDIUM
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability
Published Aug 8, 2008
5.0
MEDIUMCVSS 2.0
EPSS 1.20%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.