[GS07-02] RSA Keon Multiple Cross-Site Scripting Vulnerabilities



GS07-02 RSA Keon Multiple Cross-Site Scripting Vulnerabilities

Date & Version : 07/31/2007 - 1.0

Description :

RSA KEON Registration Authority Web Interface has multiple Cross-Site
Scripting Vulnerabilities. Request-spk.xuda and Add-msie-request.xuda
components of RSA KEON are vulnerable to Cross-Site Scripting attacks.
An attacker could use these vulnerabilities for manipulating the
registration information, phising and other client side attacks.

Risk Level : Medium

Impact : Gain Access

Systems Affected :

RSA KEON Registration Authority Software

Remedy :

Contact RSA and visit https://knowledge.rsasecurity.com for remediation.

Credits :

Fatih Ozavci (GamaTEAM Member)
Caglar Cakici (GamaTEAM Member)
It's detected using GamaSEC Exploit Framework
GamaSEC.net Security Solutions (www.gamasec.net)

Original Advisory Link :

http://www.gamasec.net/english/gs07-02.html

References :

1. CERT - Vulnerability Note VU#342793



Relevant Pages

  • Mac Security: Weekly Summary 2006-04-13
    ... This is another snoozy week for Mac OS X security. ... ramifications of installing Windows on your Macintel machine. ... Six new Windows related vulnerabilities. ... Microsoft FrontPage Server Extensions Cross-Site Scripting ...
    (comp.sys.mac.advocacy)
  • [Full-disclosure] [ MDVSA-2013:112 ] otrs
    ... Updated otrs package fixes security vulnerabilities: ... Multiple cross-site scripting vulnerabilities in Open Ticket ... Cross-site scripting vulnerability in Open Ticket Request System ... All packages are signed by Mandriva for security. ...
    (Full-Disclosure)
  • [ MDVSA-2013:112 ] otrs
    ... Updated otrs package fixes security vulnerabilities: ... Multiple cross-site scripting vulnerabilities in Open Ticket ... Cross-site scripting vulnerability in Open Ticket Request System ... All packages are signed by Mandriva for security. ...
    (Bugtraq)
  • [Full-disclosure] [ GLSA 200703-23 ] WordPress: Multiple vulnerabilities
    ... Wordpress contains several cross-site scripting, ... forgery and information leak vulnerabilities. ... Certain packages are still vulnerable. ... WordPress contains cross-site scripting or cross-site scripting forgery ...
    (Full-Disclosure)
  • [Full-disclosure] CORELAN-10-008 - Multiple vulnerabilities found in evalmsi 2.1.03
    ... 0x01: Vendor description of software ... evalsmsi 2.1.03 contains multiple vulnerabilities. ... SQL injection is possible via the script ajax.php ... - Persistent Cross-Site Scripting ...
    (Full-Disclosure)