Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link. This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing. An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server. All versions of SiteMinder are considered vulnerable at the moment.
Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link. This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing. An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server. All versions of SiteMinder are considered vulnerable at the moment.