PT-2008-3546 · Mozilla+2 · Firefox+2

Richard Brain

·

Publicado

2008-04-30

·

Atualizado

2018-10-11

·

CVE-2008-2027

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions RSA Authentication Agent version 5.3.0.258 for Web for IIS
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via an ftp URL in the url parameter to a Redirect action, particularly when accessed through certain browsers like Mozilla Firefox.
Recommendations For RSA Authentication Agent version 5.3.0.258 for Web for IIS, consider restricting access to the Redirect action or validating the url parameter to prevent redirects to unauthorized sites. As a temporary workaround, avoid using the url parameter in the Redirect action until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2027

Produtos afetados

Iis
Firefox
Rsa Authentication Agent