Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-08-06 04:00
Updated : 2024-02-04 16:31
NVD link : CVE-2004-0672
Mitre link : CVE-2004-0672
CVE.ORG link : CVE-2004-0672
JSON object : View
Products Affected
netegrity
- policy_server
- identityminder
CWE