Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Netegrity SiteMinder HTML Page Injection Vulnerability

Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link. This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing.

An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server.

All versions of SiteMinder are considered vulnerable at the moment.







 

Privacy Statement
Copyright 2009, SecurityFocus