First published: Tue Oct 09 2012(Updated: )
Multiple cross-site scripting (XSS) flaws were found in the way: 1) 'displayCRL' script of Certificate System sanitized content of 'pageStart' and 'pageSize' variables provided in the query string, 2) 'profileProcess' script of Certificate System sanitized content of 'nonce' variable provided in the query string. A remote attacker could provide a specially-crafted web page that, when visited by an unsuspecting Certificate System user would lead to arbitrary HTML or web script execution in the context of Certificate System user session.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Certificate System | <=8.1.1 | |
Redhat Certificate System | =7.1 | |
Redhat Certificate System | =7.2 | |
Redhat Certificate System | =7.3 | |
Redhat Certificate System | =8 | |
Redhat Certificate System | =8.0 | |
Redhat Certificate System | =8.1 | |
redhat/pki-common | <8.1.3-2.el5 | 8.1.3-2.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.