RSA SecurID cross site scripting

2010.02.12
Credit: s4squatch
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

Title: RSA SecurID XSS Discovered 12-11-2008 Discovered By: s4squatch of SecureState R&D Team (www.securestate.com) Vendor Notified: 10-07-2009 Vendor Response: 10-08-2009 Version: Unknown --> DLL does not contain version, therefore vendor says it is outdated and not supported. POC: https://www.website.com/WebID/IISWebAgentIF.dll?stage=useridandpasscode&referrer=Z2F&sessionid=0&postdata=get:f4e2c">60179147875&authntype=2&username=test&passcode=test[12:26] a Scott White<mailto:swhite@securestate.com> | Senior Consultant | SecureState 623.321.2660 - office | 480.440.7595 - mobile | 216.927.2801 - fax [cid:image001.png@01CAAB18.BCB231C0]<https://www.securestate.com/>


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top