|
Microsoft ISA Server Cross-Site Scripting Vulnerabilities
ISA server will output certain error pages when requests that are invalid, for whatever reason, are transmitted through it. These error pages will appear in the context of the domain that the request was made for. It has been reported that many of these error pages contain cross-site scripting vulnerabilities that allow for the execution of script code (embedded in the request URI) in the context of client requested domains. This vulnerability is reportedly similar to the one described in BID 4486. |
|
|
Privacy Statement |