| New User, Welcome! Login |
RSA EnVision Reflected XSS Hole
| From: |
"Stelios Tigkas" <stigkas gmail com> |
| To: |
bugtraq securityfocus com |
| Cc: |
|
| Subject: |
RSA EnVision Reflected XSS Hole |
| Date: |
Wed - Sep 12, 2007 02:55 AM |
#########################################
Application: RSA EnVision
Vendor: http://www.rsa.com
Version: Version 3.3.6 Build 0115
Bug: Cross-Site Scripting
Risk: Medium
Date: 12 Sept 2007
Author: Stelios Tigkas
e-mail: Stigkas at Gmail dot com
Current Employer: Fujitsu Services
List: BugTraq(SecurityFocus)
#########################################
=======
Product
=======
A Security Event Management Solution.
===
Bug
===
There is a Reflected (Type I) Cross-Site Scripting hole on the
username field, in the logon page of the EnVision application. The
following attack vector has been confirmed by the Vendor to work:
</script><script>alert(document.cookie)</script>.
RSA have been notified on 23.03.2007
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!