Vulnerabilities > CVE-2004-0672 - Cross-Site Scripting vulnerability in Netegrity IdentityMinder

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
netegrity
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

Exploit-Db

  • descriptionNetegrity IdentityMinder Web Edition 5.6 Null Byte XSS. CVE-2004-0672 . Webapps exploit for cgi platform
    idEDB-ID:24244
    last seen2016-02-02
    modified2004-07-01
    published2004-07-01
    reporter[email protected]
    sourcehttps://www.exploit-db.com/download/24244/
    titleNetegrity IdentityMinder Web Edition 5.6 Null Byte XSS
  • descriptionNetegrity IdentityMinder Web Edition 5.6 Management Interface XSS. CVE-2004-0672. Webapps exploit for cgi platform
    idEDB-ID:24245
    last seen2016-02-02
    modified2004-07-01
    published2004-07-01
    reporter[email protected]
    sourcehttps://www.exploit-db.com/download/24245/
    titleNetegrity IdentityMinder Web Edition 5.6 Management Interface XSS