Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kai Wilke

Researcher fromITaCS GmbH
#21901of 53,635
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2012-2348
5.8
2012-04-10
Microsoft · Forefront Unified Access Gateway (Uag) 2010 · CVE-2012-0146
**Name of the Vulnerable Software and Affected Versions** Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 **Description** The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. This can be exploited to trick users into revealing sensitive information. **Recommendations** For Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2012-2349
5.0
2012-04-10
Microsoft · Forefront Unified Access Gateway (Uag) 2010 · CVE-2012-0147
**Name of the Vulnerable Software and Affected Versions** Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 **Description** The issue allows remote attackers to obtain sensitive information via a crafted HTTPS request due to improper configuration of the default web site. **Recommendations** For Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1, consider reconfiguring the default web site to prevent unfiltered access until a proper fix is available.