Netegrity SiteMinder HTML Page Injection Vulnerability

Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link. This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing.

An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server.

All versions of SiteMinder are considered vulnerable at the moment.


 

Privacy Statement
Copyright 2010, SecurityFocus