RSA Authentication Agent for Web URI Redirection Vulnerability
BID:28907
Info
RSA Authentication Agent for Web URI Redirection Vulnerability
| Bugtraq ID: | 28907 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2027 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Richard Brain of ProCheckUp Ltd |
| Vulnerable: |
Rsa RSA Authentication Agent for Web 5.3 .258 Rsa RSA Authentication Agent for Web 5.3 |
| Not Vulnerable: |
Rsa RSA Authentication Agent for Web 5.3.3 .378 |
Discussion
RSA Authentication Agent for Web URI Redirection Vulnerability
RSA Authentication Agent for Web is prone to a remote URI-redirection vulnerability because the application fails to adequately sanitize user-supplied input.
A successful attack may aid in phishing-style attacks.
This issue affects RSA Authentication Agent for Web for Internet Information Services 5.3.0.258. Other versions may also be affected.
RSA Authentication Agent for Web is prone to a remote URI-redirection vulnerability because the application fails to adequately sanitize user-supplied input.
A successful attack may aid in phishing-style attacks.
This issue affects RSA Authentication Agent for Web for Internet Information Services 5.3.0.258. Other versions may also be affected.
Exploit / POC
RSA Authentication Agent for Web URI Redirection Vulnerability
To exploit this issue, an attacker must entice a victim into following a malicious URI.
The following example URI is available to demonstrate this issue:
https://www.example.com/WebID/IISWebAgentIF.dll?Redirect?url=ftp://www.example2.com/index.htm
To exploit this issue, an attacker must entice a victim into following a malicious URI.
The following example URI is available to demonstrate this issue:
https://www.example.com/WebID/IISWebAgentIF.dll?Redirect?url=ftp://www.example2.com/index.htm
Solution / Fix
RSA Authentication Agent for Web URI Redirection Vulnerability
Solution:
The reporter states that RSA Authentication Agent for Web 5.3.3.378 is available from the vendor to address this issue. Users of affected packages should contact the vendor for information on obtaining and applying fixes.
Solution:
The reporter states that RSA Authentication Agent for Web 5.3.3.378 is available from the vendor to address this issue. Users of affected packages should contact the vendor for information on obtaining and applying fixes.
References
RSA Authentication Agent for Web URI Redirection Vulnerability
References:
References: