List Info

Thread: RSA Keon Multiple Cross-Site Scripting Vulnerabilities




RSA Keon Multiple Cross-Site Scripting Vulnerabilities
user name
2007-10-24 05:04:28
GS07-02 RSA Keon Multiple Cross-Site Scripting
Vulnerabilities

Date & Version : 07/31/2007 - 1.0

Description :

RSA KEON Registration Authority Web Interface has multiple
Cross-Site
Scripting Vulnerabilities. Request-spk.xuda and
Add-msie-request.xuda
components of RSA KEON are vulnerable to Cross-Site
Scripting attacks.
An attacker could use these vulnerabilities for manipulating
the
registration information, phising and other client side
attacks.

Risk Level : Medium

Impact : Gain Access

Systems Affected :

RSA KEON Registration Authority Software

Remedy :

Contact RSA and visit https://knowledge.r
sasecurity.com for remediation.

Credits :

Fatih Ozavci (GamaTEAM Member)
Caglar Cakici (GamaTEAM Member)
It's detected using GamaSEC Exploit Framework
GamaSEC.net Security Solutions (www.gamasec.net)

Original Advisory Link :

http://ww
w.gamasec.net/english/gs07-02.html

References :

1. CERT - Vulnerability Note VU#342793

[1]

about | contact  Other archives ( Real Estate discussion Medical topics )