First published: Fri Jun 20 2003(Updated: )
Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSA ACE Agent | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0389 is considered to be a moderate severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2003-0389, it is recommended to upgrade to a later version of RSA ACE/Agent that addresses this vulnerability.
CVE-2003-0389 specifically affects RSA ACE/Agent version 5.0 for Windows and version 5.x for Web.
CVE-2003-0389 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Yes, CVE-2003-0389 can potentially allow attackers to insert scripts that may lead to the theft of sensitive user information.