CVE-2003-0389

Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rsa:ace_agent:5.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html - Exploit, Patch, Vendor Advisory () http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html - Exploit, Patch, Vendor Advisory
References () http://www.rapid7.com/advisories/R7-0014.html - Exploit, Patch, Vendor Advisory () http://www.rapid7.com/advisories/R7-0014.html - Exploit, Patch, Vendor Advisory

Information

Published : 2003-07-24 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0389

Mitre link : CVE-2003-0389

CVE.ORG link : CVE-2003-0389


JSON object : View

Products Affected

rsa

  • ace_agent