Sun iPlanet contains a flaw that may allow an attacker to inject an arbitrary URL into an error page. The issue is due to a non-existent URL received via the HTTP referer header being used in the error page output. The resulting error page will use an HTML href element to render the link, only showing "referring page". While minor, this type of attack may assist in social engineering attacks.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
OSVDB is not aware of a solution for this vulnerability.