|  Sun Java Server Faces Input Handling Cross-Site Scripting
Sunday, 16 March 2008Description:Sun has acknowledged a vulnerability in Java Server Faces, which can be exploited by malicious people to conduct cross-site scripting attacks.
 
 Input passed to unspecified Java Server Faces (JSF) input handling routines is not properly sanitised. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a site using an affected JSF version.
 
 The vulnerability is reported in Sun Java Server Faces 1.2. Other versions may also be affected.
 
 Solution:
 Update to Sun Java Server Faces 1.2_08 or later:
 http://javaserverfaces.dev.java.net/
 
 Provided and/or discovered by:
 Reported by the vendor.
 
 Changelog:
 2008-03-12: Added CVE reference.
 
 Original Advisory:
 http://sunsolve.sun.com/search/document.do?assetkey=1-66-233561-1
 
 http://secunia.com/advisories/29327/
 
 Share this content:
 
         | 
|---|