New User, Welcome!     Login

RSA EnVision Reflected XSS Hole

From: "Stelios Tigkas" <stigkas gmail com>
To: bugtraq securityfocus com
Cc:
Subject: RSA EnVision Reflected XSS Hole
Date: Wed - Sep 12, 2007 02:55 AM


#########################################
Application:           RSA EnVision
Vendor:                http://www.rsa.com
Version:                Version 3.3.6 Build 0115
Bug:                     Cross-Site Scripting
Risk:                     Medium
Date:                     12 Sept 2007
Author:                  Stelios Tigkas
e-mail:                   Stigkas at Gmail dot com
Current Employer:   Fujitsu Services
List:                       BugTraq(SecurityFocus)
#########################################


=======
Product
=======
A Security Event Management Solution.

===
Bug
===

There is a Reflected (Type I) Cross-Site Scripting hole on the
username field, in the logon page of the EnVision application. The
following attack vector has been confirmed by the Vendor to work:
</script><script>alert(document.cookie)</script>.

RSA have been notified on 23.03.2007




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!