Netegrity SiteMinder HTML Page...

- AV AC AU C I A
发布: 2005-01-17
修订: 2025-04-13

Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link. This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing. An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server. All versions of SiteMinder are considered vulnerable at the moment.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息