Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=108881203114336&w=2 - | |
References | () http://www.securityfocus.com/bid/10645 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16618 - |
Information
Published : 2004-08-06 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0672
Mitre link : CVE-2004-0672
CVE.ORG link : CVE-2004-0672
JSON object : View
Products Affected
netegrity
- policy_server
- identityminder
CWE