First published: Wed Apr 15 2009(Updated: )
Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security And Acceleration Server | =2006-supportability | |
Microsoft Internet Security And Acceleration Server | =2004-sp3 | |
Microsoft Forefront Threat Management Gateway | ||
Microsoft Internet Security And Acceleration Server | =2006-sp1 | |
Microsoft Internet Security And Acceleration Server | =2004-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.