First published: Mon Mar 24 2008(Updated: )
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSA WebID | =5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1470 is classified as high due to its potential to enable cross-site scripting attacks.
To fix CVE-2008-1470, upgrade to the latest version of the RSA WebID Authentication Agent that addresses this vulnerability.
CVE-2008-1470 enables remote cross-site scripting (XSS) attacks via manipulation of the postdata parameter.
CVE-2008-1470 affects RSA WebID Authentication Agent version 5.3 and possibly earlier versions.
Yes, the known solution for CVE-2008-1470 is to apply patches provided by RSA for the affected software.