First published: Mon Jul 11 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA SiteMinder | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2204 is classified as a moderate severity vulnerability as it allows for cross-site scripting attacks.
To mitigate CVE-2005-2204, ensure that the 'CSSChecking' parameter is set to 'YES' and apply security patches from Broadcom.
CVE-2005-2204 affects CA eTrust SiteMinder version 5.5.
CVE-2005-2204 can be exploited through the PASSWORD, BUFFER, and TARGET parameters in smpwservicescgi.exe.
CVE-2005-2204 can allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data and sessions.