RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
BID:7972
Info
RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7972 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0389 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | This vulnerability was discovered independantly by both Rapid7 Security and RSA Security. |
| Vulnerable: |
Rsa ACE/Agent for Windows 5.0 Rsa ACE/Agent for Web 5.0 |
| Not Vulnerable: |
Rsa ACE/Agent for Windows 5.0.1 Rsa ACE/Agent for Web 5.1.1 |
Discussion
RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
The RSA SecurID ACE Agent is reported to be prone to a cross-site scripting vulnerability. An attacker could exploit this issue to creating a malicious link to a site hosting the software that contains hostile HTML and script code. If this link is visited by a web user, the attacker-supplied code could be interpreted in their browser.
The RSA SecurID ACE Agent is reported to be prone to a cross-site scripting vulnerability. An attacker could exploit this issue to creating a malicious link to a site hosting the software that contains hostile HTML and script code. If this link is visited by a web user, the attacker-supplied code could be interpreted in their browser.
Exploit / POC
RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
Solution:
The following upgraded versions are available:
Rsa ACE/Agent for Web 5.0
Rsa ACE/Agent for Windows 5.0
Solution:
The following upgraded versions are available:
Rsa ACE/Agent for Web 5.0
-
RSA Security WebAgent5.1.1.tar.gz
ftp://ftp.rsasecurity.com/support/Patches/Ace/Agent/5.1.1_Agent/WebAge nt5.1.1.tar.gz
Rsa ACE/Agent for Windows 5.0
-
RSA Security Win_Agent501.zip
ftp://ftp.rsasecurity.com/support/Patches/Ace/Agent/5.0.1_Agent/Win_Ag ent501.zip
References
RSA SecurID ACE Agent Cross-Site Scripting Vulnerability
References:
References:
- RSA SecurID ACE Agent Cross Site Scripting (Rapid7)
- SecurID Product Homepage (RSA Security)