[NT] RSA ClearTrust Cross Site Scripting Issues

From: support@securiteam.com
Date: 03/19/03

  • Next message: support@securiteam.com: "[UNIX] Vulnerabilities in the Kerberos Version 4 Protocol"
    From: support@securiteam.com
    To: list@securiteam.com
    Date: 19 Mar 2003 13:43:48 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    In the US?

    Contact Beyond Security at our new California office
    housewarming rates on automated network vulnerability
    scanning. We also welcome ISPs and other resellers!

    Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
    - - - - - - - - -

      RSA ClearTrust Cross Site Scripting Issues
    ------------------------------------------------------------------------

    SUMMARY

    The <http://www.rsasecurity.com> RSA ClearTrust is a Web access
    management solution that helps enable secure access to Web-based
    resources. RSA ClearTrust software is designed to work within intranets,
    extranets, portals and exchange infrastructures - all while providing
    users with transparent, single sign-on (SSO) across multiple applications.

    A cross-site scripting vulnerability in the product allows an attacker to
    insert malicious HTML and JavaScript into the existing logon screen.

    DETAILS

    RSA ClearTrust login page suffers from a Cross Site Scripting
    vulnerabilities:
    https://victim.com/cleartrust/ct_logon.asp?CTLoginErrorMsg=<
    script>alert(1)</script>
    https://victim.com/cleartrust/ct_logon.asp?CTAuthMode=BASIC&CTLoginErrorMsg=xx&ct_orig_uri=">< script>alert(1)/script><"

    Vendor status:
    Vendor contacted, no reply has been received.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:sir.mordred@hushmail.com>
    Sir Mordred.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: support@securiteam.com: "[UNIX] Vulnerabilities in the Kerberos Version 4 Protocol"

    Relevant Pages

    • [UNIX] DSH HOME Environment Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get Thawte's New Step-by-Step SSL Guide for MSIIS ... This vulnerability will allow attackers to cause the product crash. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [UNIX] Owl Intranet Engine Security Bypassing
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Owl is a multi user document repository ... A vulnerability in the product allows remote attackers to ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [NEWS] Directory Traversal Vulnerability in Phpimglist
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Phpimglist creates a gallery images from a certain directory. ... There is a vulnerability in phpimglist which allows a user to traverse ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [EXPL] Zeroo Webserver Remote Directory Traversal Exploit
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Vulnerability> Zeroo Folder Traversal Vulnerability, ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [EXPL] Remote Heap malloc/free and Multiple Overflow Vulnerability in WSMP3 (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WsMp3 versions ... # Remote Heap malloc/free & multiple Overflow vulnerability in WSMP3. ... to $Host \n"; ...
      (Securiteam)

  • Quantcast