Description: Marc Ruef has reported some vulnerabilities in Sun Secure Global Desktop Software, which can be exploited by malicious people to conduct cross-site scripting attacks.
Unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Certain system information disclosures have also been reported.
The vulnerabilities have been reported in version 4.2 prior to build 4.20.983.
Solution: Update to version 4.2 build 4.20.983 or later.
Provided and/or discovered by: Mark Ruef
Changelog: 2006-10-02: Updated "Title", and "Description" and "Solution" section. Added additional information provided by the vendor about affected versions.
2006-12-14: Added link to US-CERT.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.