PT-2008-3037 · Rsa · Webid Rsa Authentication Agent
Quentin Berdugo
·
Publicado
2008-03-24
·
Atualizado
2018-10-11
·
CVE-2008-1470
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WebID RSA Authentication Agent version 5.3 and possibly earlier
Description
The issue is related to an incomplete blacklist vulnerability in the IISWebAgentIF.dll component. This allows remote attackers to conduct cross-site scripting (XSS) attacks via the
postdata parameter, due to an incomplete fix for a previously known issue.Recommendations
For WebID RSA Authentication Agent version 5.3 and possibly earlier, consider restricting access to the
postdata parameter in the affected API endpoint until a comprehensive fix is available. As a temporary workaround, avoid using the postdata parameter to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webid Rsa Authentication Agent