Advisory Name: Cross-Site Scripting (XSS) in Blackberry WebDesktop Internal Cybsec Advisory Id: 2011-0401 Vulnerability Class: Cross-Site Scripting (XSS) Release Date: 12/04/2011 Affected Applications: . BlackBerry Enterprise Server Express versions 5.0.1 and 5.0.2 for Microsoft Exchange . BlackBerry Enterprise Server Express version 5.0.2 for IBM Lotus Domino . BlackBerry Enterprise Server versions 5.0.0 through 5.0.3 for Microsoft Exchange and IBM Lotus Domino . BlackBerry Enterprise Server version 5.0.1 for Novell GroupWise Affected Platforms: Blackberry Enterprise Server Local / Remote: Remote Severity: Medium - CVSS: 3.5 (AV:N/AC:M/Au:S/C:P/I:N/A:N) Researcher: Ivan Huertas Vendor Status: Patched Reference to Vulnerability Disclosure Policy: http://www.cybsec.com/vulnerability_policy.pdf Vulnerability Description: A Cross Site Scripting vulnerability was found in Blackberry WebDektop, because the application fails to sanitize user-supplied input. The vulnerability can be triggered if a logged user follows a specially crafted link, executing malicious Javascript code on the user's browser. Proof of Concept: Inserting