CVE-2008-1470: XSS
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1470?
The severity of CVE-2008-1470 is classified as high due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2008-1470?
To fix CVE-2008-1470, upgrade to the latest version of the RSA WebID Authentication Agent that addresses this vulnerability.
What kind of attacks does CVE-2008-1470 enable?
CVE-2008-1470 enables remote cross-site scripting (XSS) attacks via manipulation of the postdata parameter.
Which software versions are affected by CVE-2008-1470?
CVE-2008-1470 affects RSA WebID Authentication Agent version 5.3 and possibly earlier versions.
Is there a known solution for CVE-2008-1470?
Yes, the known solution for CVE-2008-1470 is to apply patches provided by RSA for the affected software.