PT-2010-1169 · Microsoft · Forefront Unified Access Gateway

Eyal Gruner

·

Publicado

2010-11-09

·

Atualizado

2018-10-12

·

CVE-2010-3936

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Forefront Unified Access Gateway versions 2010 Gold, 2010 Update 1, and 2010 Update 2
Description The issue is related to a lack of protection for the web page structure in the Signurl.asp component. This allows a remote attacker to perform cross-site scripting (XSS) attacks, which can enable the injection of arbitrary web scripts or HTML.
Recommendations For Microsoft Forefront Unified Access Gateway versions 2010 Gold, 2010 Update 1, and 2010 Update 2, consider restricting access to the Signurl.asp component until a patch is available. As a temporary workaround, avoid using the Signurl.asp component in sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-04412
CVE-2010-3936

Produtos afetados

Forefront Unified Access Gateway