Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
BID:49972
Info
Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
| Bugtraq ID: | 49972 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1896 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Apr 19 2013 02:40AM |
| Credit: | Tenable Network Security |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
Microsoft Forefront Unified Access Gateway is prone to a cross-site scripting vulnerability because Web Monitor fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal potentially sensitive information and launch other attacks.
Microsoft Forefront Unified Access Gateway is prone to a cross-site scripting vulnerability because Web Monitor fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal potentially sensitive information and launch other attacks.
Exploit / POC
Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Solution / Fix
Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
Solution:
The vendor has released an advisory and updates. Please see the referenced advisory for details.
References
Microsoft Forefront Unified Access Gateway (CVE-2011-1896) Cross-Site Scripting Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS11-079 (Microsoft)