PT-2008-3037 · Rsa · Webid Rsa Authentication Agent
Quentin Berdugo
·
Published
2008-03-24
·
Updated
2018-10-11
·
CVE-2008-1470
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WebID RSA Authentication Agent version 5.3 and possibly earlier
Description
The issue is related to an incomplete blacklist vulnerability in the IISWebAgentIF.dll component. This allows remote attackers to conduct cross-site scripting (XSS) attacks via the
postdata parameter, due to an incomplete fix for a previously known issue.Recommendations
For WebID RSA Authentication Agent version 5.3 and possibly earlier, consider restricting access to the
postdata parameter in the affected API endpoint until a comprehensive fix is available. As a temporary workaround, avoid using the postdata parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webid Rsa Authentication Agent